Is Pago pendiente (1)-1.pdf safe?
Multiple high-trust detections and offensive sandbox mappings make this new payment-themed PDF risky, although no strong family consensus or independently confirmed payload emerged.
Five of 75 engines flagged this recently observed PDF, including three independent tier-1 votes, and one sandbox mapped credential dumping, process injection, and data destruction techniques. However, that sandbox returned a clean verdict, no inspected child was identified as malware, and no strong family or external-intelligence consensus exists.
58878fcb9e5732f458…d28a4b2677690eRecommended next actions
Before opening
Do not open it until the source can be verified independently.
If you already opened it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from the original trusted source and verify its exact hash when possible.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Five of 75 engines flagged this recently observed PDF, including three independent tier-1 votes, and one sandbox mapped credential dumping, process injection, and data destruction techniques. However, that sandbox returned a clean verdict, no inspected child was identified as malware, and no strong family or external-intelligence consensus exists.
The strongest concern is that 5 of 75 engines detected the PDF, with three independent tier-1 malicious votes. Avast and AVG use a MalwareX scam label, while Avira and F-Secure report generic PDF.Agent heuristics, so the labels do not establish a strong common family. One completed sandbox run mapped T1003, T1055, and T1485, but its own verdict was clean and the mappings do not by themselves prove those actions originated from the document. The two observed domains had no cached malicious or suspicious reputation, though complete reputation coverage for the contacted IP addresses is not available. Ten inspected children produced no identified malicious child, and neither YARAify nor MalwareBazaar supplied corroboration. The file is also only one day old with two submissions, leaving insufficient history to dismiss the detections as established false positives.
What We Detected
Five of 75 antivirus engines flagged this 4,009-byte AcroForm PDF. Three independent tier-1 votes were recorded: Avast and AVG displayed PDF:MalwareX-gen [Scam], while Avira and F-Secure supplied generic PDF.Agent heuristic labels. The family consensus is not strong, and several major engines—including BitDefender, ESET-NOD32, Kaspersky, Microsoft, and Fortinet—reported no detection.
Threat Behavior
One completed sandbox run opened the document through Adobe Acrobat and mapped T1003, T1055, and T1485. These are serious offensive-technique mappings, but the sandbox verdict itself was clean, and the saved evidence does not conclusively show that the PDF caused credential dumping, process injection, or data destruction. Both observed domains were checked without cached malicious or suspicious findings; the contacted IP addresses were not shown as fully covered. None of 10 inspected child hashes was identified as malicious, and no YARAify or MalwareBazaar match corroborated a malware family.
What To Do Now
Do not open the document on a production system or enter payment, login, or personal information through it. Verify the alleged payment request using a separately obtained phone number or official account portal, keep endpoint protection enabled, and delete or quarantine the file if its source cannot be independently authenticated.
Where this verdict could be wrong5 caveats
- behaviour.hasMaliciousSandboxVerdict=false: the only completed sandbox run returned a clean verdict despite the offensive-technique mappings.
- 13 tier-1 engines reported no detection, including BitDefender, ESET-NOD32, Kaspersky, Microsoft, and Fortinet.
- contactedHosts inspected both observed domains and found no cached malicious or suspicious entries, although the contacted IP addresses were not shown as covered.
- externalIntel.malwareBazaar.hit=false and externalIntel.yaraify.hit=false, so no researcher-curated source independently corroborated the detections.
- All 10 inspected dropped children remain unclassified rather than malicious; droppedChildren.hasMaliciousChild=false.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- behaviour.hasMaliciousSandboxVerdict=false
- droppedChildren.hasMaliciousChild=false across 10 inspected children
- externalIntel.yaraify.ruleCount=0
- externalIntel.malwareBazaar.hit=false
- 13 tier-1 engines reported no detection
- 5/75 antivirus detections
- engines.tier1Malicious=3
- Payment-themed PDF observed only one day ago
- MITRE mappings T1003, T1055, and T1485
- AcroForm content may support deceptive interaction
- No established prevalence or signer history applies
Quarantine the PDF and verify the payment request through an independent, trusted channel before taking action. Keep endpoint protection enabled and avoid opening the file on a production device.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete5 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial2 of 4 contacted hosts were cross-checked; coverage is incomplete.
YARA
Complete2 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 15MITRE ATT&CK techniques
- 9spawned processes
- 4network contacts
- 37filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Accessed operating-system credential data, which can expose saved passwords.
High concern: Injected code into another process, a technique that can conceal execution.
Moderate concern: Contained obfuscated or packed code that makes inspection harder.
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
Moderate concern: Checked the environment for virtualisation or analysis tools.
Note: Reads your Windows user-account details.
Note: Collects details about your system.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
Pago pendiente (1)-1.pdf
58878fcb9e5732f458697fd5cd346441470d26848414e10c60d28a4b2677690e
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\<USER>\Desktop\Pago pendiente _1_.pdf"
02Isolated runtime analysis - ProcessObserved
Observed process
"C:\Program Files\Adobe\Acrobat DC\Acrobat\Adobe Crash Processor.exe"
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
acroNGLLog.txt
C:\Users\<USER>\AppData\Local\Temp\acroNGLLog.txt
04Isolated runtime analysis - Written fileObserved
NGL
C:\Users\<USER>\AppData\Local\Temp\NGL\
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
acroipm2.adobe.com
Contact observed during runtime.
06Isolated runtime analysis - Contacted hostObserved
atm.teams.mira.tm.svc.cloud.microsoft
Contact observed during runtime.
07Isolated runtime analysis - +1 more recorded observation in Analyst mode
7 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- acroipm2.adobe.com
- atm.teams.mira.tm.svc.cloud.microsoft
- 8.8.8.8
- 162.159.36.2
- HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\7b\52C64B7E\@%systemroot%\system32\wsdapi.dll,-200
- HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\7b\52C64B7E\@C:\Windows\System32\AppxPackaging.dll,-1001
- HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\7b\52C64B7E\@%SystemRoot%\System32\SessEnv.dll,-101
- HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\7b\52C64B7E\@%SystemRoot%\System32\CertCA.dll,-304
- HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\7b\52C64B7E\@%SystemRoot%\System32\CertCA.dll,-305
- Software\Adobe\Acrobat Reader\DC\ExitSection\bLastExitNormal
- C:\Users\<USER>\AppData\Local\Temp\acroNGLLog.txt
- C:\Users\<USER>\AppData\Local\Temp\NGL\
- C:\Users\<USER>\AppData\Local\Temp\Tmp178A.tmp
- C:\Users\<USER>\AppData\Local\Temp\Tmp1902.tmp
- C:\Users\<USER>\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Reader\SOPHIA.json
- C:\Users\<USER>\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettings
- C:\Users\<USER>\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Reader\Files\DC_READER_LAUNCH_CARD
- C:\Users\<USER>\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Reader\Files\ACROBAT_READER_MASTER_SURFACEID
- C:\Users\<USER>\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages-journal
- C:\Users\<USER>\AppData\Local\Temp\Cab5A70.tmp
- Global\_MSIExecute
- Global\MSILOG_f6d442f91dd54d2GOL.72231ISM_pmeT_lacoL_ataDppA_onurB_sresU_:C
- Global\AdobeCrashProcessorLocalLowLock
- \Sessions\1\BaseNamedObjects\{100184D2-BDC3-477a-B8D3-65548B67914C}_4032
- \Sessions\1\BaseNamedObjects\Local\{100184D2-BDC3-477a-B8D3-65548B67914C}_2356
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- eacad3e01b8b0a44ac03…df796dNever scannednever seen before
- a779a261df447a4c298c…b1b86dNever scannednever seen before
- ad27039abac3252c3b39…37ede5Never scannednever seen before
- 7149b6c95eddc22d45df…ab192fNever scannednever seen before
- 81ff65efc4487853bdb4…7c8e06Never scannednever seen before
- 2ef9ff16f6b28caaeb84…8ce2c1Never scannednever seen before
- 59fcb2c9c213c5427c3e…09d49bNever scannednever seen before
- e3b0c44298fc1c149afb…52b855Never scannednever seen before
- a5c6d4dbae668479ccb9…11631bNever scannednever seen before
- 4df98d996551189e28df…fe1f0dNever scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 2rule hits recorded
- 5 / 75engines flagged
- 2sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 high-confidence signature or behavior rule matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 02
5 of 75 antivirus engines flagged the file, including Avast and AVG.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 03
The hash has been submitted 2 times from 2 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: Pago pendiente (1)-1.pdf — 58878fcb9e5732f458697fd5cd346441470d26848414e10c60d28a4b2677690e
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\<USER>\Desktop\Pago pendiente _1_.pdf"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — "C:\Program Files\Adobe\Acrobat DC\Acrobat\Adobe Crash Processor.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: acroNGLLog.txt — C:\Users\<USER>\AppData\Local\Temp\acroNGLLog.txt
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: NGL — C:\Users\<USER>\AppData\Local\Temp\NGL\
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: acroipm2.adobe.com — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 10
Contacted host: atm.teams.mira.tm.svc.cloud.microsoft — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
Category: generic-trojan
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
EvidenceC:\Windows\Explorer.EXEMITRE T1003 (OS Credential Dumping) mapped by at least one sandbox run.
5 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Barely seen in the wild and first surfaced recently. 5 antivirus detections make that low prevalence materially relevant, but rarity alone is not proof of malware.
Fingerprint and provenance
- File name
- Pago pendiente (1)-1.pdf
- Format
- Code signing
- Not applicable to this file type
- Size
- 3.9 KB
- Last analyzed
- Oct 6, 2026, 3:20 PM UTC
58878fcb9e5732f458697fd5cd346441470d26848414e10c60d28a4b2677690eSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't open it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
If its origin cannot be confirmed, delete this file and use a fresh copy from a trusted source. Get a fresh copy from the original trusted source and verify its exact hash when possible.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is Pago pendiente (1)-1.pdf safe, or is it malware?
What is Pago pendiente (1)-1.pdf?
How many antivirus engines detected Pago pendiente (1)-1.pdf?
I already downloaded and opened Pago pendiente (1)-1.pdf — what should I do?
How do I remove Pago pendiente (1)-1.pdf?
What kind of malware is Pago pendiente (1)-1.pdf?
What is the SHA-256 hash of Pago pendiente (1)-1.pdf?
How up to date is this analysis of Pago pendiente (1)-1.pdf?
Community
Member reviews and reports for this exact file hash.