Is SPUC.pdf safe?
Three high-trust detections identify phishing traits in this newly observed PDF, but absent runtime evidence and weak family consensus prevent a definitive malware attribution.
Five of 74 engines flagged the PDF, with three independent high-trust detections and repeated phishing-oriented labels. Because the file is newly observed and lacks runtime results, host-reputation coverage, or strong family consensus, it should not be opened or trusted without source verification.
1881e1be19fc60a710…5a0ebca82b6419Recommended next actions
Before opening
Do not open it until the source can be verified independently.
If you already opened it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from the original trusted source and verify its exact hash when possible.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Five of 74 engines flagged the PDF, with three independent high-trust detections and repeated phishing-oriented labels. Because the file is newly observed and lacks runtime results, host-reputation coverage, or strong family consensus, it should not be opened or trusted without source verification.
Five of 74 engines detected the document, and three independent high-trust votes make the signal meaningful. Avira and F-Secure identify a phishing-oriented PDF.Agent pattern, while Avast and AVG use a generic MalwareX phishing label. However, the family consensus is not strong, and 13 tier-1 engines reported no detection. The sample has only one recorded submission and no established reputation. No completed runtime observation or complete contacted-host reputation result is available, so the document's interactive behavior and possible destinations remain unverified.
What We Detected
Five of 74 antivirus engines flagged this PDF. Three independent high-trust detections are recorded, with Avira and F-Secure identifying PDF.Agent phishing patterns and Avast/AVG using a generic MalwareX phishing label. The labels point toward a phishing document, but they do not form strong consensus on a specific malware family.
Threat Behavior
The PDF carries AcroForm content, which can support interactive form fields but is not harmful by itself. No completed sandbox run is available, so there is no observed evidence showing whether the document presents credential prompts, opens links, or performs other actions. Contacted-host reputation was not checked or saved, leaving any possible destinations unassessed.
What To Do Now
Do not open the document or enter credentials unless its sender and purpose can be independently verified. Keep endpoint protection enabled, and obtain a fresh copy through a trusted official channel if the document was expected.
Where this verdict could be wrong3 caveats
- 13 tier-1 engines reported no detection, including BitDefender, ESET-NOD32, Kaspersky, Microsoft, and Fortinet.
- externalIntel.yaraify.ruleCount=0, externalIntel.circl.hit=false, and externalIntel.malwareBazaar.hit=false provide no independent malicious corroboration.
- engines.tier1FamilyConsensus.strong=false, so no malware family has strong independent tier-1 agreement.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 13 tier-1 engines reported no detection
- No strong tier-1 family consensus
- No YARAify, CIRCL, or MalwareBazaar corroboration
- No malicious dropped child was reported
- Three independent high-trust antivirus votes
- Repeated phishing-oriented PDF.Agent labels
- Newly observed file with only one submission
- Interactive AcroForm PDF content
- No completed runtime analysis
- No complete contacted-host reputation result
Quarantine the PDF and verify its origin through a separate trusted channel before opening it. Keep security protections enabled and avoid entering credentials into forms presented by the document.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete5 of 74 engines flagged the file.
Sandbox
PartialRuntime data is present, but no completed sandbox environment is recorded.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime behavior was not available
The report does not treat a missing runtime observation as a clean result.
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 5 / 74engines flagged
- 1sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
5 of 74 antivirus engines flagged the file, including Avast and AVG.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 1 time from 1 source.
ProvenanceDerivedSourceSaved report factsObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
5 of 74 engines flagged this file
View all 74 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Barely seen in the wild and first surfaced recently. 5 antivirus detections make that low prevalence materially relevant, but rarity alone is not proof of malware.
Fingerprint and provenance
- File name
- SPUC.pdf
- Format
- Code signing
- Not applicable to this file type
- Size
- 32.0 KB
- Last analyzed
- Sep 16, 2026, 11:36 AM UTC
1881e1be19fc60a710e3b00abae105a45ad68bb4e048e38c345a0ebca82b6419Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't open it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
If its origin cannot be confirmed, delete this file and use a fresh copy from a trusted source. Get a fresh copy from the original trusted source and verify its exact hash when possible.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is SPUC.pdf safe, or is it malware?
What is SPUC.pdf?
How many antivirus engines detected SPUC.pdf?
I already downloaded and opened SPUC.pdf — what should I do?
How do I remove SPUC.pdf?
What is the SHA-256 hash of SPUC.pdf?
How up to date is this analysis of SPUC.pdf?
Community
Member reviews and reports for this exact file hash.