
Old Allaple Worm Label Reused on Adobe-Masquerading HTML Droppers
Three HTML files tagged trojan.allaple by VirusTotal disguise themselves as Adobe Acrobat DC resource files and embed base64-obfuscated JavaScript. One sample cleared a sandbox with a 99%-confidence clean verdict despite tripping 26 of 77 antivirus engines, while a bundled 2015 Win32 binary shares no build lineage with the 2024 cohort. Broad, low-detection IP telemetry across four unrelated carrier networks and three countries points to opportunistic scanning rather than provisioned command infrastructure.
Three HTML files carrying VirusTotal's family label "trojan.allaple" — 1102b8a9933b2191f1b80bd9bc478f301536216332ddf2986d3ffc792474be3d, 7768dae586920feac88943b260caa4f9a26bd357603d81517431d38f5e026594, and eb333a956be00c99c0d2523fabbea40f08ce65f5120e2744a24a5fb3abbfa3b7 — were submitted between April and August 2024, and two of them stage themselves under file paths built to look like legitimate Adobe software.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read