CLEAN
22
Risk Score
Machine Learning
- Nyx PDF Classifier clean score 0.0001
Heuristics 2
-
Callback phishing phone lure medium SE_CALLBACK_LUREDocument asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) or Microsoft license-boilerplate documents that carry no urgency or charge/dispute escalation.
-
External URI info PDF_URIPDF contains an external URL action
Extracted artifacts 6
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_012_off00024249.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x24249 | 151220 bytes |
SHA-256: 254fc6d9978b371a457f3202913e2e0fd79df9a658a1c7269bbf765c0363c3d4 |
|||
font_00_sfnt_off0001f56e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1F56E | 31016 bytes |
SHA-256: e5837f96200d1e2cab5c44df487bb113424c457d7c4b9fccffbd26cb7bcf059e |
|||
font_02_sfnt_off0002d1ee.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x2D1EE | 23056 bytes |
SHA-256: 327e9f319e5d949b83ded288749f16da83c81296ca3b772e33efb0c75417754e |
|||
font_03_sfnt_off00030a19.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x30A19 | 48556 bytes |
SHA-256: 58d9ebcbe2ae3b4a9f56fc8f8345500cb002cf1bf2d5e0c4a5293b39c9e01ddf |
|||
font_04_sfnt_off0003887e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3887E | 217340 bytes |
SHA-256: 94e96ca5dcf0707727b48752fdd01a4cb343919f3b48cba95a6cbc0d6d0c748e |
|||
font_05_sfnt_off0003af71.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3AF71 | 47796 bytes |
SHA-256: e63a51dfd52b6a8c3166c59ef4814eb245c5181b09637107ec97ab4eb48e1cf5 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.