MALICIOUS
62
Risk Score
Machine Learning
- Nyx PDF Classifier clean score 0.0001
Heuristics 2
-
Travel-support phone-number stuffing scam critical SE_TRAVEL_SUPPORT_PHONE_SCAMDocument repeats phone numbers in airline/travel/refund/support language, often across multiple regional phrasings. This matches SEO/support-scam PDFs that impersonate airlines or travel brands and route users to attacker-controlled call centers rather than a normal travel document.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.microsoft.com/typography/ctfontshttp://fontfabrik.comYou In extracted file (stream_010_off0003279f.bin)
- http://www.microsoft.com/typography/fonts/default.aspxIn extracted file (stream_010_off0003279f.bin)
- http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl0XIn extracted file (stream_010_off0003279f.bin)
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0In extracted file (stream_010_off0003279f.bin)
- http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl0aIn extracted file (stream_010_off0003279f.bin)
- http://www.microsoft.com/pkiops/certs/MicCodSigPCA2011_2011-07-08.crt0In extracted file (stream_010_off0003279f.bin)
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0TIn extracted file (stream_010_off0003279f.bin)
- http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0In extracted file (stream_010_off0003279f.bin)
- http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl0^In extracted file (stream_010_off0003279f.bin)
- http://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0��In extracted file (stream_010_off0003279f.bin)
- http://www.microsoft.com/pkiops/docs/primarycps.htm0@In extracted file (stream_010_off0003279f.bin)
- http://www.microsoft.com/TypographyIn extracted file (stream_010_off0003279f.bin)
- https://www.verisign.com/repository/CPS��In extracted file (font_00_sfnt_off00019d96.bin)
- https://www.verisign.comIn extracted file (font_00_sfnt_off00019d96.bin)
- https://www.verisign.com/repository/verisignlogo.gif06In extracted file (font_00_sfnt_off00019d96.bin)
- http://status.verisign.com/class1.crl0In extracted file (font_00_sfnt_off00019d96.bin)
- http://www.microsoft.com/typographyIn extracted file (font_00_sfnt_off00019d96.bin)
- http://crl.microsoft.com/pki/crl/products/CSPCA.crl0HIn extracted file (font_03_sfnt_off00046d23.bin)
- http://www.microsoft.com/pki/certs/CSPCA.crt0In extracted file (font_03_sfnt_off00046d23.bin)
- http://crl.microsoft.com/pki/crl/products/tspca.crl0HIn extracted file (font_03_sfnt_off00046d23.bin)
- http://www.microsoft.com/pki/certs/tspca.crt0In extracted file (font_03_sfnt_off00046d23.bin)
Extracted artifacts 5
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_001_off00004b76.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x4B76 | 304722 bytes |
SHA-256: 19b7ef7954e2b2f26f22499636db64b2b4674aaf790111ab9b03b517b1abef1a |
|||
stream_010_off0003279f.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x3279F | 178104 bytes |
SHA-256: 8a8fc56d0163e128630612f434daab1cfee4554b92725012322ebe1473cb6abc |
|||
font_00_sfnt_off00019d96.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x19D96 | 15320 bytes |
SHA-256: 2d1d62d3deb09e558c5e1e7254ebf5de94a490deb079a2d268a5411865f30a59 |
|||
font_01_sfnt_off0001c2b7.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1C2B7 | 187720 bytes |
SHA-256: b6e578c0757bef231fbbf7c3cb2bbd8ffba676e182941e8abcdaaa854a6e1034 |
|||
font_03_sfnt_off00046d23.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x46D23 | 39984 bytes |
SHA-256: 42e7928f9e3c4084f6ec37d09cbef43c93b735dacadaac70c3772635c0edd2a4 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.