Suspicious
PDF triggers multiple sandbox heuristics for process injection and credential access despite zero AV detections.
5667173fe607d76c67…cf35a68442The reasoning behind this verdict
The MT AI Engine weighs every signal from this scan — antivirus detections, sandbox behaviour, code signing, prevalence and historical matches — to reach a single, evidence-based verdict.
The complete absence of engine detections across tier-1 and tier-2 vendors weighs toward benign, but three high-to-medium severity heuristics fired on credential-dumping, process-injection and direct-IP C2 behaviour. The file is a recently submitted PDF executed inside Acrobat, which can legitimately touch some system areas yet does not explain LSASS access or no-DNS IP contact. Medium prevalence with no prior similar-hash verdicts and no signer history prevents a clean classification. The combination of strong behavioural red flags against unanimous engine silence produces a borderline mixed-signals assessment.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines: 0 malicious detections out of 74 total (16 tier-1 clean)
behaviour.offensiveTechniques: T1003, T1055, T1485 observed in sandbox
triggeredHeuristics: MalwareTips.Synth.ProcessInjection (high severity) and MalwareTips.Synth.DirectIpC2 (medium severity)
contactedIps: direct contact to 8.8.8.8 with zero domains
prevalence.classification: medium (6 submitters, 6 submissions)
- Zero detections across 63 reporting engines
- No malicious dropped children
- No external intelligence hits
- Sandbox heuristics flagged credential access and process injection
- Direct-IP contact without DNS usage
- Unsigned PDF with only 5 days of history
Treat as suspicious pending further prevalence growth or additional sandbox corroboration; avoid execution until more data is available.
What this file does
What it attempted when executed in an isolated sandbox
High concern: Tries to steal saved passwords and credentials from Windows.
High concern: Hides inside another running program to evade antivirus.
High concern: Talks to a remote server to take commands or send out your data.
Moderate concern: Checks whether it's being watched in a sandbox before acting.
Note: Reads your Windows user-account details.
Note: Collects details about your system.
Translated from the file's technical behaviour during analysis. It never ran on your device.
What to do now
We couldn't fully clear this file. Treat it with caution.
Don't run it unless you're certain it came from a source you trust.
Check where you got it — an email attachment or a random download link is a red flag.
If you're unsure, delete it. You can always re-download a clean copy from the official source.
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 8.8.8.8
- C:\Users\<USER>\AppData\Local\Temp\acroNGLLog.txt
- C:\Users\<USER>\AppData\Local\Temp\NGL\
- C:\Users\<USER>\AppData\Local\Temp\TmpEF9F.tmp
- C:\Users\<USER>\AppData\Local\Temp\TmpF0AA.tmp
- C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmp
- C:\Users\<USER>\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettings
- C:\Users\<USER>\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache\KnownGameList.bin
- C:\Users\<USER>\AppData\Local\Microsoft\GameDVR\KnownGameList.update
- C:\Users\<USER>\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Reader\Files\DC_READER_LAUNCH_CARD
- C:\Users\<USER>\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Reader\Files\ACROBAT_READER_MASTER_SURFACEID
- Global\_MSIExecute
- Global\MSILOG_5ed8414e1dd152fGOL.5f001ISM_pmeT_lacoL_ataDppA_onurB_sresU_:C
- Global\AdobeCrashProcessorLocalLowLock
- \Sessions\1\BaseNamedObjects\{100184D2-BDC3-477a-B8D3-65548B67914C}_6212
- \Sessions\1\BaseNamedObjects\Local\{100184D2-BDC3-477a-B8D3-65548B67914C}_996
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- eacad3e01b8b0a44ac03…df796dNever scannednever seen before
- a779a261df447a4c298c…b1b86dNever scannednever seen before
- ad27039abac3252c3b39…37ede5Never scannednever seen before
- a10c66bee1738dd6dff2…7c25e2Never scannednever seen before
- 81ff65efc4487853bdb4…7c8e06Never scannednever seen before
- bdc1aafb3b03d8559726…e6cbe0Never scannednever seen before
- 5932b8ba9c8e6e55fb98…2ae6f9Never scannednever seen before
- e3b0c44298fc1c149afb…52b855Never scannednever seen before
- aeb4d4eaf64889cb277f…d4a5dbNever scannednever seen before
- a5c6d4dbae668479ccb9…11631bNever scannednever seen before
YARA & heuristic rule matches
A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.
MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.
EvidenceC:\Windows\Explorer.EXESandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exeSample contacted 1 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence8.8.8.8
0 detections across 74 engines
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Forensic fingerprint
- File name
- GWM.pdf
- Size
- 307.0 KB
- MIME type
- (unknown)
- Detected type
- SHA-256
- 5667173fe607d76c679bbdcfb732113a492ea5d57ddba7023df07bcf35a68442
- MD5
- 7a5230f5bea86644c6f6c5b639090785
- SHA-1
- b4804b42c2b8232291766f05b49109c00f09b2c8
- First seen (VT)
- 7/16/2026, 3:27:35 AM
- Last analysis (VT)
- 7/16/2026, 3:27:35 AM
- First scan (MalwareTips)
- 7/21/2026, 7:47:42 AM
- Last scan (MalwareTips)
- 7/21/2026, 7:47:42 AM
Safety FAQ
Common questions about GWM.pdf, answered from the scan data above.
- GWM.pdf is suspicious — treat it as unsafe until you're sure. 0 of 74 antivirus engines flag it, which isn't a strong consensus but is enough to be cautious. Don't opened it unless you fully trust where it came from, and prefer downloading the software fresh from its official site.
- GWM.pdf is a document file, about 307 KB. We identify a file by its cryptographic hash rather than its name, because the same filename can be reused by completely different files — the hash below is the reliable fingerprint.
- None — all 74 antivirus engines we queried report GWM.pdf as clean. That's reassuring, though brand-new malware can briefly evade detection before vendors add signatures, so we also weigh the file's behaviour and reputation.
- Act quickly. 1) Disconnect the device from the internet to stop the malware communicating or spreading. 2) Run a full scan with reputable anti-malware software (such as Malwarebytes) and quarantine everything it finds. 3) Change your important passwords from a DIFFERENT, clean device — many threats log keystrokes or steal saved credentials. 4) If you bank or shop on this device, watch closely for fraud and alert your bank. 5) For a confirmed infection, the most reliable fix is to back up your personal files and reinstall the operating system for a clean start.
- To remove GWM.pdf: 1) restart into Safe Mode (Safe Mode with Networking if you need to download a tool) so the malware doesn't auto-start. 2) Run a full scan with reputable anti-malware software and let it quarantine or delete the detections. 3) Delete the original GWM.pdf file and empty the Recycle Bin/Trash. 4) Check your browser extensions, startup items, and scheduled tasks for anything unfamiliar. 5) Reboot and scan again to confirm it's gone. If detections keep coming back, a clean operating-system reinstall is the most dependable cure.
- The SHA-256 hash of GWM.pdf is 5667173fe607d76c679bbdcfb732113a492ea5d57ddba7023df07bcf35a68442, and its MD5 is 7a5230f5bea86644c6f6c5b639090785. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
- This report reflects the scan run on July 21, 2026. Because a file's hash never changes, the identity of GWM.pdf is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.