logo

The PDF Scanner Couldn't Open the Attachment (But the Victim Could)

ID: 1831c51f-f478-567b-a69c-53c06d2c8546

STIX ID: report--1831c51f-f478-567b-a69c-53c06d2c8546

Feed Name: IRONSCALES

Threat Score
65/100

Date Published: 2026-04-18

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

TL;DR: A spearphishing email impersonating the Georgia Department of Education delivered a password-protected PDF (112,382 bytes) with the passcode provided in the email body (0937728736), enabling a human recipient to open the encrypted payload while automated scanners, unable to decrypt the file, returned clean verdicts; IRONSCALES flagged and quarantined the message. The report provides IOCs (sender domain and email, attachment name and MD5 hash, embedded image hash, linked domains), maps the behavior to MITRE ATT&CK techniques T1566.001 and T1027, and emphasizes the need for context-aware detection beyond static file scanning.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.