Malicious PDF — malware analysis report

Static analysis result for SHA-256 f6882ceeb6d43bfb…

MALICIOUS

PDF

72.5 KB First seen: 2026-07-16
MD5: b4a21959a44f19dee303a01f8307e90a SHA-1: 2db82600a5292579cf870a3e08dae00c7d929652 SHA-256: f6882ceeb6d43bfbcc718629faf325cc474ea40b10d357183efb5687f36f7231
62 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0004

Heuristics 2

  • Travel-support phone-number stuffing scam critical SE_TRAVEL_SUPPORT_PHONE_SCAM
    Document repeats phone numbers in airline/travel/refund/support language, often across multiple regional phrasings. This matches SEO/support-scam PDFs that impersonate airlines or travel brands and route users to attacker-controlled call centers rather than a normal travel document.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.adobe.com/ In extracted file (font_00_sfnt_off000028b8.bin)

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000028b8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x28B8 17364 bytes
SHA-256: b1e5ef16a9b57e7c75fdcc49476a722025965af8f19152099f647759e3765f1d
font_01_sfnt_off0000370a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x370A 12148 bytes
SHA-256: 05f2880d41a630b12b4b16d5802fa7fa55dbd4a3a2a266457090cfc8fd0a00c9
font_02_sfnt_off000039c9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x39C9 10504 bytes
SHA-256: 4c355a6944451c700d478d00727b956b782d12a76635e7b5d93f18f62b0b68bd
font_03_sfnt_off0000502f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x502F 8136 bytes
SHA-256: 4e5295134975ef2e56f1214c0a25d028af7729290952485aa4dd12469cf3ee6c
font_04_sfnt_off00005313.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5313 6072 bytes
SHA-256: 9df00d5a184f04132bdd99f4a1a11249859af296b9c318be76c8c07b1c3737d0