The PDF Scanner Couldn't Open the Attachment (But the Victim Could)
ID: 1831c51f-f478-567b-a69c-53c06d2c8546
STIX ID: report--1831c51f-f478-567b-a69c-53c06d2c8546
Feed Name: IRONSCALES
TL;DR: A spearphishing email impersonating the Georgia Department of Education delivered a password-protected PDF (112,382 bytes) with the passcode provided in the email body (0937728736), enabling a human recipient to open the encrypted payload while automated scanners, unable to decrypt the file, returned clean verdicts; IRONSCALES flagged and quarantined the message. The report provides IOCs (sender domain and email, attachment name and MD5 hash, embedded image hash, linked domains), maps the behavior to MITRE ATT&CK techniques T1566.001 and T1027, and emphasizes the need for context-aware detection beyond static file scanning.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
