Is Proposal.pdf safe?
No antivirus engine detected the PDF, and its completed sandbox run produced no malicious verdict, dropped payload, persistence activity, or network contact.
All 75 antivirus engines returned without a detection, including 17 high-trust engines. One completed sandbox run found no malicious verdict, MITRE technique, dropped payload, persistence action, or network contact, although the newly observed file has limited reputation history.
6bdd2b30b61eb0b2eb…1499f9db69e94eRecommended next actions
Before opening
Open it only when its sender or download source is one you independently trust.
If you already opened it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 75 antivirus engines returned without a detection, including 17 high-trust engines. One completed sandbox run found no malicious verdict, MITRE technique, dropped payload, persistence action, or network contact, although the newly observed file has limited reputation history.
The strongest evidence is complete agreement across the antivirus network: 0 of 75 engines flagged the PDF. Seventeen high-trust engines, including Microsoft, Kaspersky, BitDefender, Avast, and ESET-NOD32, reported no detection. A completed sandbox run produced no malicious verdict and recorded no techniques, dropped files, persistence, or network activity. MalwareBazaar, YARAify, and CIRCL provided no matching intelligence. The main limitation is that the file was first observed today and has only one submission, while the five prior PDF-format matches offer only weak contextual support.
What We Detected
None of the 75 antivirus engines flagged the PDF, and all 17 reporting tier-1 engines returned without a detection. MalwareBazaar, YARAify, and CIRCL also had no matching intelligence for this hash.
Threat Behavior
One completed sandbox run produced no malicious verdict. It recorded no MITRE techniques, spawned processes, dropped hashes, persistence indicators, or network contacts. A separate contacted-host reputation result was not available, but there were no observed hosts to cross-check in this run.
What To Do Now
The evidence supports ordinary handling of the document. Because it is newly observed and has little reputation history, keep endpoint protection enabled and confirm the sender if the proposal arrived unexpectedly or requests unusual follow-up actions.
Where this verdict could be wrong2 caveats
- prevalence.classification=rare_new with file.ageDays=0 and one submission means the PDF has little established reputation.
- contactedHosts=null, so no complete contacted-host reputation result is available; however, the sandbox recorded no contacted domains, IPs, or URLs.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/75 antivirus engines detected a threat
- 17 tier-1 engines reported no detection
- Completed sandbox run had no malicious verdict
- No dropped payloads, persistence indicators, or observed network contacts
- No MalwareBazaar, YARAify, or CIRCL match
- Newly observed file with one submission and no established reputation
- No saved contacted-host reputation cross-check
Normal use is reasonable based on the available evidence. Keep endpoint protection enabled and verify the sender if the document was unsolicited.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 0MITRE ATT&CK techniques
- 0spawned processes
- 0network contacts
- 0filesystem & mutex artifacts
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 0 / 75engines flagged
- 1sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 75 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 1 time from 1 source.
ProvenanceDerivedSourceSaved report factsObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
0 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Barely seen in the wild and first surfaced recently. That limits reputation evidence, but rarity alone is not proof of malware.
Fingerprint and provenance
- File name
- Proposal.pdf
- Format
- Code signing
- Not applicable to this file type
- Size
- 160.3 KB
- Last analyzed
- Oct 7, 2026, 2:19 PM UTC
6bdd2b30b61eb0b2ebf1083b97ff088f1f6a899f2717e760831499f9db69e94eSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Open it only when its sender or download source is one you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is Proposal.pdf safe?
What is Proposal.pdf?
How many antivirus engines detected Proposal.pdf?
What is the SHA-256 hash of Proposal.pdf?
Is it safe to open Proposal.pdf?
How up to date is this analysis of Proposal.pdf?
Community
Member reviews and reports for this exact file hash.