SUSPICIOUS
52
Risk Score
Machine Learning
- Nyx PDF Classifier clean score 0.0006
Heuristics 4
-
PDF link to algorithmically-generated URL high PDF_RANDOM_URL_LINKPDF contains a clickable HTTP(S) link whose host looks algorithmically generated (pronounceable-random labels) and whose path/query carries a long high-entropy token. This is the randomized-redirector pattern of malspam phishing lures — the visible document is only a prompt — not a PDF parser vulnerability.
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://api-qm0j4twx2.rainbowmanseeyou.mom/ PDF link annotation
- https://apc01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.phillife.com.ph%2F&data=05%7C02%7Cmajhoannagracev%40phillife.com.ph%7C8cd86cb7415643f80fd008de8ba19d24%7C7cc2411d654b46c5aefef08401ab01ba%7C0%7C0%7C639101723408579543%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=5UdR%2FV1WgU%2BqYoqVTA2Np7oQ2cXvVlFlAzsSax0gCV0%3D&reserved=0In PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/pdfx/1.3/In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- https://apc01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.phillife.com.ph%2F&data=05%7C02%7Cmajhoannagracev%40phillife.com.ph%7C8cd86cb7415643f80fd008de8ba19d24%7C7cc2411d654b46c5aefef08401ab01ba%7C0%7C0%7C639101723408579543%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwIn PDF document text
- https://docs.microsoft.com/typography/abouthttp://lucasfonts.comMicrosoftIn extracted file (stream_002_off00004f06.bin)
- http://en.wikipedia.org/wiki/MIT_LicenseIn extracted file (stream_002_off00004f06.bin)
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_002_off00004f06.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x4F06 | 300008 bytes |
SHA-256: 2adc1eba178fb611ad6a478be5366bd6cb7e5b4f31f9adaea09dc3955036edf4 |
|||
stream_003_off00019415.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x19415 | 341892 bytes |
SHA-256: 5e45933ef39eccf9e95cd194de4d1e1d679cb72598e289093673e408f6e1d9c0 |
|||
font_02_sfnt_off00033a2b.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x33A2B | 19552 bytes |
SHA-256: 4ced48352fec30c970f5afc2206ab51c851b13828d48dddc174a64881ec1ef94 |
|||
font_03_sfnt_off00035ce6.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x35CE6 | 54744 bytes |
SHA-256: f724eca65d77454858e0a868ba6bb8eb08f971ad3aebc3be315bb4b56ddf008a |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.