🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fd3cc838775e561688cc53ea92eb17b25557181797103324e2adee6793dee770. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: fd3cc838775e561688cc53ea92eb17b25557181797103324e2adee6793dee770
SHA3-384 hash: 1043d446d5514d7aa20fc6009ca3ff025f53fa28348af842a2d2072a604ca844219bd5c5d7b1107d61e16e5e4c315455
SHA1 hash: 7ffd86762317ed173083bce8f9a61e8ba69ccbbc
MD5 hash: 82d077b89a59a61d88adfa89d55d744a
humanhash: hamper-carolina-nitrogen-burger
File name:Pdf_431582580190226.pdf
Download: download sample
File size:61'428 bytes
First seen:2026-02-19 08:10:31 UTC
Last seen:Never
File type:Java file jar
MIME type:application/octet-stream
ssdeep 1536:U8djHzbKXZkuAm/MbByEB7GL3//mfJWe+vCc7gfkCW5/tpISR:UU/5Ask+o/mvc7g8//NR
TLSH T180539CF60959DC8AEF8B66B3FD532D89C6E870FE02D4D7A13427450AD40449DBB2389E
TrID 66.6% (.SER) Java serialization stream (v5) (4000/1)
33.3% (.SER) Java serialization stream (generic) (2000/1)
Magika pdf
Reporter abuse_ch
Tags:jar pdf

Intelligence


File Origin
# of uploads :
1
# of downloads :
152
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Result
Threat name:
n/a
Detection:
suspicious
Classification:
evad
Score:
21 / 100
Signature
Uses an obfuscated file name to hide its real file extension (double extension)
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1871793 Sample: Pdf_431582580190226.pdf.jar Startdate: 19/02/2026 Architecture: WINDOWS Score: 21 12 Uses an obfuscated file name to hide its real file extension (double extension) 2->12 6 cmd.exe 1 2->6         started        process3 process4 8 conhost.exe 6->8         started        10 java.exe 1 6->10         started       
Threat name:
Binary.Trojan.Generic
Status:
Suspicious
First seen:
2026-02-19 09:10:33 UTC
AV detection:
3 of 38 (7.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
adware discovery evasion pdf spyware
Behaviour
Checks processor information in registry
Modifies Internet Explorer settings
Suspicious behavior: EnumeratesProcesses
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments