File verdict·Decided by the MT AI Engine
Our call

Suspicious

PDF triggers multiple sandbox heuristics for process injection and credential access despite zero AV detections.

Trust score45Caution
GWM.pdf
307.0 KB
5667173fe607d76c67cf35a68442
Antivirus engines
0 of 74 flagged
Code signing
Unsigned
Age
First seen 5 days ago
MT AI Engine · Verdict analysis

The reasoning behind this verdict

The MT AI Engine weighs every signal from this scan — antivirus detections, sandbox behaviour, code signing, prevalence and historical matches — to reach a single, evidence-based verdict.

65%Confidence
High
Reasoning

The complete absence of engine detections across tier-1 and tier-2 vendors weighs toward benign, but three high-to-medium severity heuristics fired on credential-dumping, process-injection and direct-IP C2 behaviour. The file is a recently submitted PDF executed inside Acrobat, which can legitimately touch some system areas yet does not explain LSASS access or no-DNS IP contact. Medium prevalence with no prior similar-hash verdicts and no signer history prevents a clean classification. The combination of strong behavioural red flags against unanimous engine silence produces a borderline mixed-signals assessment.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. engines: 0 malicious detections out of 74 total (16 tier-1 clean)

  2. behaviour.offensiveTechniques: T1003, T1055, T1485 observed in sandbox

  3. triggeredHeuristics: MalwareTips.Synth.ProcessInjection (high severity) and MalwareTips.Synth.DirectIpC2 (medium severity)

  4. contactedIps: direct contact to 8.8.8.8 with zero domains

  5. prevalence.classification: medium (6 submitters, 6 submissions)

Points in its favour
  • Zero detections across 63 reporting engines
  • No malicious dropped children
  • No external intelligence hits
Points against
  • Sandbox heuristics flagged credential access and process injection
  • Direct-IP contact without DNS usage
  • Unsigned PDF with only 5 days of history
Recommended action

Treat as suspicious pending further prevalence growth or additional sandbox corroboration; avoid execution until more data is available.

What this file does

What it attempted when executed in an isolated sandbox

  • High concern: Tries to steal saved passwords and credentials from Windows.

  • High concern: Hides inside another running program to evade antivirus.

  • High concern: Talks to a remote server to take commands or send out your data.

  • Moderate concern: Checks whether it's being watched in a sandbox before acting.

  • Note: Reads your Windows user-account details.

  • Note: Collects details about your system.

Translated from the file's technical behaviour during analysis. It never ran on your device.

What to do now

We couldn't fully clear this file. Treat it with caution.

  1. Don't run it unless you're certain it came from a source you trust.

  2. Check where you got it — an email attachment or a random download link is a red flag.

  3. If you're unsure, delete it. You can always re-download a clean copy from the official source.

  4. If you're still unsure, scan it again in a day or two — detections often catch up on newer files.

Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
13

Adversary techniques mapped to the MITRE ATT&CK framework.

T1003· Credential theftT1012T1033· Reads user infoT1036T1047T1055· Process injectionT1071· Remote server (C2)T1082· System reconT1485T1497· Sandbox evasionT1564· Hides artifactsT1564.003· Hides artifactsT1573
Spawned processes
15
$(unnamed)
"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\<USER>\Desktop\GWM-1.pdf"
$(unnamed)
"C:\Program Files\Adobe\Acrobat DC\Acrobat\Adobe Crash Processor.exe"
$(unnamed)
C:\Windows\Explorer.EXE
$(unnamed)
"C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe" "C:\Program Files\Adobe\Acrobat DC\Acrobat" updatepvbpreference 92688ba9-2b4d-4bbe-a373-367ec25022c0 0 0
$(unnamed)
"C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe" "C:\Program Files\Adobe\Acrobat DC\Acrobat" "C:\Users\<USER>\AppData\LocalLow\Adobe\CRLogs\crashlogs"
$(unnamed)
C:\Windows\system32\services.exe
$(unnamed)
"C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe" "C:\Program Files\Adobe\Acrobat DC\Acrobat" "C:\Users\<USER>\AppData\LocalLow\Adobe\CRLogs\dumps"
$(unnamed)
C:\Windows\System32\svchost.exe -k NetworkService -p
+7 more processes captured.
Network activity
1
IP addresses1
  • 8.8.8.8
Filesystem & mutexes
38
Files written15
  • C:\Users\<USER>\AppData\Local\Temp\acroNGLLog.txt
  • C:\Users\<USER>\AppData\Local\Temp\NGL\
  • C:\Users\<USER>\AppData\Local\Temp\TmpEF9F.tmp
  • C:\Users\<USER>\AppData\Local\Temp\TmpF0AA.tmp
  • C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmp
+10 more
Files deleted14
  • C:\Users\<USER>\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettings
  • C:\Users\<USER>\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache\KnownGameList.bin
  • C:\Users\<USER>\AppData\Local\Microsoft\GameDVR\KnownGameList.update
  • C:\Users\<USER>\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Reader\Files\DC_READER_LAUNCH_CARD
  • C:\Users\<USER>\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Reader\Files\ACROBAT_READER_MASTER_SURFACEID
+9 more
Mutexes created9
  • Global\_MSIExecute
  • Global\MSILOG_5ed8414e1dd152fGOL.5f001ISM_pmeT_lacoL_ataDppA_onurB_sresU_:C
  • Global\AdobeCrashProcessorLocalLowLock
  • \Sessions\1\BaseNamedObjects\{100184D2-BDC3-477a-B8D3-65548B67914C}_6212
  • \Sessions\1\BaseNamedObjects\Local\{100184D2-BDC3-477a-B8D3-65548B67914C}_996
+4 more
Dropped payload

Files this sample writes at runtime

This file drops 10 children at runtime. None are currently flagged malicious in our cache.

10 unseen
  • eacad3e01b8b0a44ac03df796dNever scanned
    never seen before
  • a779a261df447a4c298cb1b86dNever scanned
    never seen before
  • ad27039abac3252c3b3937ede5Never scanned
    never seen before
  • a10c66bee1738dd6dff27c25e2Never scanned
    never seen before
  • 81ff65efc4487853bdb47c8e06Never scanned
    never seen before
  • bdc1aafb3b03d8559726e6cbe0Never scanned
    never seen before
  • 5932b8ba9c8e6e55fb982ae6f9Never scanned
    never seen before
  • e3b0c44298fc1c149afb52b855Never scanned
    never seen before
  • aeb4d4eaf64889cb277fd4a5dbNever scanned
    never seen before
  • a5c6d4dbae668479ccb911631bNever scanned
    never seen before
No researcher-database hits
External threat-intel sources were not collected for this scan.
Signature matches

YARA & heuristic rule matches

A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.

3 synthesis
MITRE ATT&CK profile
Defense evasion× 1Cred access× 1C2× 1
MalwareTips synthesis rules
Our own detection rules, applied to the scan data and sandbox behaviour
  • ProcessInjectionhigh

    MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.

    Evidence
    C:\Windows\Explorer.EXE
  • CredentialDumpermedium

    Sandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.

    Evidence
    C:\Windows\system32\lsass.exe
  • DirectIpC2medium

    Sample contacted 1 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.

    Evidence
    8.8.8.8
Antivirus engine breakdown

0 detections across 74 engines

0 malicious0 suspicious74 clean
Tier-117 engines
0flag
Top commercial AVs (low FP rate)
Tier-240 engines
0flag
Mainstream engines with mixed FP rates
Low-trust17 engines
0flag
Heuristic / generic-AI engines (high FP rate)
All 74 engines report this file as clean.
Hash 5667173fe607… cross-referenced against 74 AV engines via our AV network.
Prevalence

How widely this file has been seen

Moderate prevalence — neither rare nor common. No strong prior applies.

Medium
Unique uploaders
6
Moderate upload volume.
Total submissions
6
Includes repeat uploads by the same source.
First seen
5d ago
Jul 16, 2026
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
7/16/2026, 3:27:35 AM
First seen (MalwareBazaar)
Last analysis (VT)
7/16/2026, 3:27:35 AM
Scanned here
7/21/2026, 7:47:42 AM
File name
GWM.pdf
Size
307.0 KB
MIME type
(unknown)
Detected type
PDF
SHA-256
5667173fe607d76c679bbdcfb732113a492ea5d57ddba7023df07bcf35a68442
MD5
7a5230f5bea86644c6f6c5b639090785
SHA-1
b4804b42c2b8232291766f05b49109c00f09b2c8
First seen (VT)
7/16/2026, 3:27:35 AM
Last analysis (VT)
7/16/2026, 3:27:35 AM
First scan (MalwareTips)
7/21/2026, 7:47:42 AM
Last scan (MalwareTips)
7/21/2026, 7:47:42 AM
Behavior tags
pdfacroformidleattachment
Frequently asked

Safety FAQ

Common questions about GWM.pdf, answered from the scan data above.

  • GWM.pdf is suspicious — treat it as unsafe until you're sure. 0 of 74 antivirus engines flag it, which isn't a strong consensus but is enough to be cautious. Don't opened it unless you fully trust where it came from, and prefer downloading the software fresh from its official site.
  • GWM.pdf is a document file, about 307 KB. We identify a file by its cryptographic hash rather than its name, because the same filename can be reused by completely different files — the hash below is the reliable fingerprint.
  • None — all 74 antivirus engines we queried report GWM.pdf as clean. That's reassuring, though brand-new malware can briefly evade detection before vendors add signatures, so we also weigh the file's behaviour and reputation.
  • Act quickly. 1) Disconnect the device from the internet to stop the malware communicating or spreading. 2) Run a full scan with reputable anti-malware software (such as Malwarebytes) and quarantine everything it finds. 3) Change your important passwords from a DIFFERENT, clean device — many threats log keystrokes or steal saved credentials. 4) If you bank or shop on this device, watch closely for fraud and alert your bank. 5) For a confirmed infection, the most reliable fix is to back up your personal files and reinstall the operating system for a clean start.
  • To remove GWM.pdf: 1) restart into Safe Mode (Safe Mode with Networking if you need to download a tool) so the malware doesn't auto-start. 2) Run a full scan with reputable anti-malware software and let it quarantine or delete the detections. 3) Delete the original GWM.pdf file and empty the Recycle Bin/Trash. 4) Check your browser extensions, startup items, and scheduled tasks for anything unfamiliar. 5) Reboot and scan again to confirm it's gone. If detections keep coming back, a clean operating-system reinstall is the most dependable cure.
  • The SHA-256 hash of GWM.pdf is 5667173fe607d76c679bbdcfb732113a492ea5d57ddba7023df07bcf35a68442, and its MD5 is 7a5230f5bea86644c6f6c5b639090785. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
  • This report reflects the scan run on July 21, 2026. Because a file's hash never changes, the identity of GWM.pdf is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.