FILEMembers
FILE

Fake Adobe Acrobat DC Folder Hides Base64-Obfuscated URL

Two HTML files mimic real Adobe Acrobat DC resource paths, with one triggering a YARA rule for a Base64-encoded URL embedded in JavaScript. But the surrounding indicator set—including ten IPs sitting in ordinary Verizon Business carrier space—is too thin to support a campaign narrative.

Sep 5, 2026, 22:40 (UTC+9)Last seenSep 5, 2026Severity60ByCTX TeamIOC45MITRE25RegionsUS

Three HTML files carrying the generic "trojan.allaple" label look, at first glance, like leftovers from a worm outbreak that antivirus vendors have tracked for the better part of two decades. Buried in their metadata, though, is a more specific and more current story: two of the three files were captured with internal path names placing them inside a real Adobe Acrobat DC installation tree — C:\Program Files\Adobe\Acrobat DC\Acrobat\ngl_resources\resources\ui\index.html and C:\Program…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence