MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8aae82dfe337761e498f8509c66b54f7ffb59896606869739f22f6b8a07ab64c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 8aae82dfe337761e498f8509c66b54f7ffb59896606869739f22f6b8a07ab64c
SHA3-384 hash: 2710587a5a79e024b9bbf1e494e2dda9e4e2139cba4f1e5de0e9b43ed4d2cd1e310a585ccb30beb4e75683172cd3d229
SHA1 hash: 382714d4fee0668bf257f7b5c028c18879354f37
MD5 hash: 5d6cb2bf977bc91dfeb22dba13aa5a9d
humanhash: sierra-fillet-green-stairway
File name:8aae82dfe337761e498f8509c66b54f7ffb59896606869739f22f6b8a07ab64c.pdf
Download: download sample
File size:584'213 bytes
First seen:2026-04-07 23:02:04 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 12288:hTwrQP5MAb4zv/zAhu/J/3FTPntJ0Le5BUb6cGZiNS:h76AMzvzJ1TPtJ0Le/zCS
TLSH T137C42354A0852F6DFBFD59726128395A4FF9A2A31ED532F4122E5EB788C4E24C093F07
Magika pdf
Reporter johnk3r
Tags:104-249-10-197 ClickFix kak-is latam oficiospolicia-com pdf sg.plantaalagoas-al-gov-br xx-kak-is

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
obfuscated qrcode soft-404
Label:
Benign
Suspicious Score:
/10
Score Malicious:
1%
Score Benign:
99%
Verdict:
Unknown
File Type:
pdf
First seen:
2026-04-08T22:28:00Z UTC
Last seen:
2026-04-09T08:57:00Z UTC
Hits:
~10
Result
Threat name:
CAPTCHA Scam ClickFix
Detection:
malicious
Classification:
phis.evad
Score:
76 / 100
Signature
AI detected malicious page (phishing or scam)
AI detected malicious PDF file
Antivirus detection for URL or domain
Encrypted powershell cmdline option found
HTML page adds supicious text to clipboard
Yara detected CAPTCHA Scam ClickFix
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1894975 Sample: sPgh8eeRy8.pdf Startdate: 08/04/2026 Architecture: WINDOWS Score: 76 38 xx.kak.is 2->38 64 Antivirus detection for URL or domain 2->64 66 AI detected malicious page (phishing or scam) 2->66 68 Yara detected CAPTCHA Scam ClickFix 2->68 70 2 other signatures 2->70 9 cmd.exe 1 2->9         started        12 chrome.exe 2->12         started        14 chrome.exe 2 2->14         started        17 4 other processes 2->17 signatures3 process4 dnsIp5 74 Encrypted powershell cmdline option found 9->74 19 powershell.exe 12 9->19         started        22 conhost.exe 9->22         started        24 chrome.exe 12->24         started        52 192.168.2.4 unknown unknown 14->52 54 192.168.2.5 unknown unknown 14->54 56 192.168.2.6, 138, 443, 49695 unknown unknown 14->56 27 chrome.exe 14->27         started        58 127.0.0.1 unknown unknown 17->58 29 AcroCEF.exe 104 17->29         started        signatures6 process7 dnsIp8 72 Encrypted powershell cmdline option found 19->72 31 powershell.exe 15 19 19->31         started        40 sistemas.cabo.pe.gov.br 130.185.238.40, 443, 49715, 49716 PROTECSERVICOSDESEGURANCAELETRONICALTDABR Bulgaria 24->40 42 prodoc.ap.gov.br 177.84.201.149, 443, 49720, 49721 PRODAP-CentrodeGestaodaTecnologiaeInformacaoBR Brazil 24->42 50 2 other IPs or domains 24->50 44 104.249.10.197, 443, 49734, 49735 SEABONE-NETTELECOMITALIASPARKLESpAIT United States 27->44 46 sg.plantaalagoas.al.gov.br 186.249.58.68, 443, 49738, 49739 INSTDETECNEMINFEINFDOESTDEALBR Brazil 27->46 48 142.251.151.119, 443, 49736, 49751 GOOGLEUS United States 27->48 34 AcroCEF.exe 3 29->34         started        signatures9 process10 dnsIp11 60 xx.kak.is 172.67.171.129, 443, 49743, 49744 CLOUDFLARENETUS United States 31->60 36 conhost.exe 31->36         started        62 72.247.96.179, 443, 49701 AKAMAI-ASUS United States 34->62 process12
Gathering data
Threat name:
Document-PDF.Trojan.Heuristic
Status:
Malicious
First seen:
2026-04-07 23:02:30 UTC
File Type:
Document
Extracted files:
17
AV detection:
8 of 38 (21.05%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments