← All posts

Delivery & payments

Save: PDF PDF Transaction and and save a physical copy | Suspicious email review

The reporter says they made no such purchase, and the invoice email gives no item or amount. We classify it as suspected phishing and explain what to check before acting.

The email says an invoice for a recent purchase is attached. It comes with one PDF, and the body lists a support phone number. But the reporter says they made no such purchase. With no explanation of what was bought in the body either, we reviewed the message as a suspected phishing case.

The subject asks the recipient to save the PDF and keep a physical copy, but repeats the words ‘PDF PDF’ and ‘and and.’ The attachment filename uses the same wording. That awkward phrasing stands out, though it is not enough on its own to establish phishing.

Reconstructed invoice email with recipient details and the phone number redacted

A reconstruction of the email body with personal information redacted. This is not the original inbox view. Remote images and the contents of the PDF are not shown.

An invoice with no purchase details in the body

The body gives no item or amount to compare with a transaction. It lists a support number without explicitly asking the recipient to call. No links were found in the email body examined.

The short English invoice notice is followed by a long Spanish legal and confidentiality notice. It names COEMTAL, while the sender address uses the domain etchegoyen[.]cl. Their relationship to the actual seller has not been established. Adding legal boilerplate does not make an invoice trustworthy.

The headers report authentication passes

The supplied headers report SPF, DKIM, and DMARC passes, and the sender and return-path domains match. Those results do not establish that the invoice itself is genuine. Headers can be forged or describe a different delivery hop; this review read the results recorded in the original email without independently verifying them.

If you receive the same email

Start by comparing the invoice with purchase records in the seller’s familiar official app or an official website you access directly. If you need help, use contact details from an existing contract or the official website instead of the number in the email. For a work email, you can ask your organization’s security team to review the message.

Based on the reporter’s statement that they made no such purchase and the lack of specific transaction details in the body, we classify this email as suspected phishing. The purchase information comes from the reporter; we have not independently checked their transaction records.

This review did not analyze the contents of the PDF. No links were visited, and no attachments were executed or malware-scanned. Whether the attachment is malicious and how the message might be used to cause harm remain unverified.

PDF 첨부청구서거래 확인이메일 인증