Invitation_Farewell_DE_EMB.pdf.bin.pdf

Classification: Malicious

Invitation_Farewell_DE_EMB.pdf.bin.pdf is a malicious file sample. Linked to Apt29 activity. Reported by 3 threat sources, last seen 2026-08-31.

Detection summary

  • 35 antivirus detections (58% detection ratio)
  • 0 IDS alerts
  • 6 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Intrusion sets: APT29 (G0016)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Cyber Threat Alliance 2026-07-27 10:20:40 2026-08-31 10:10:53 malicious-activity
Apt 29 Maltiverse 2023-08-18 04:15:27 2023-08-19 20:21:53 malicious-activity G0016 APT29
Generic Malware Hybrid-Analysis 2023-08-16 02:45:04 2023-08-16 02:45:04

Tags

apt

Sample information

Filenames
Invitation_Farewell_DE_EMB.pdf.bin.pdf
File type
PDF document, version 1.3
Size
302346 bytes
MD5
fc53c75289309ffb7f65a3513e7519eb
SHA-1
7c983eeac2f60abaaf49bc349dfb7079b716d6a3
SHA-256
302c0d553c9e7f2561864d79022b780a53ec0a5927e8962d883b88dde249d044
First indexed
2023-08-16 02:32:04
Last updated
2025-12-17 07:07:43

Antivirus detections

EngineDetection
LionicTrojan.PDF.Agent.4!c
FireEyeTrojan.GenericKD.68283668
ALYacTrojan.GenericKD.68283668
ArcabitTrojan.Generic.D411ED14
VirITTrojan.PDF.Agent.BBW
CyrenJS/Agent.BYE
SymantecTrojan.Gen.NPE
ESET-NOD32PDF/TrojanDropper.Agent.CJ
TrendMicro-HouseCallTrojan.PDF.GRAPHICALPROTON.YXDHAZ
AvastOther:Malware-gen [Trj]
CynetMalicious (score: 99)
KasperskyTrojan-Dropper.HTML.Agent.cn
BitDefenderTrojan.GenericKD.68283668
NANO-AntivirusTrojan.Script.Dropper.eszsqk
MicroWorld-eScanTrojan.GenericKD.68283668
TencentPdf.Trojan-Dropper.Per.Ychl
EmsisoftTrojan.GenericKD.68283668 (B)
F-SecureHeuristic.HEUR/MalSource.buhvt
DrWebExploit.Siggen3.42248
VIPRETrojan.GenericKD.68283668
TrendMicroTrojan.PDF.GRAPHICALPROTON.YXDHAZ
McAfee-GW-EditionBehavesLike.PDF.Evasion.dx
AviraHEUR/MalSource.buhvt
Antiy-AVLTrojan/Win32.Leonem
GridinsoftPDF.Exploit.JS
MicrosoftTrojan:Win32/Leonem
ViRobotPDF.Z.Agent.302346
ZoneAlarmTrojan-Dropper.HTML.Agent.cn
GDataTrojan.GenericKD.68283668
GoogleDetected
McAfeeArtemis!FC53C7528930
MAXmalware (ai score=82)
IkarusTrojan-Dropper.PDF.Agent
FortinetPDF/Agent.BLOB!tr.dldr
AVGOther:Malware-gen [Trj]

Process list

NameCommand line
AcroRd32.exe"C:\Invitation_Farewell_DE_EMB.pdf.bin.pdf"
RdrCEF.exe--backgroundcolor=16448250
RdrCEF.exe--type=renderer --primordial-pipe-token=62F67FFA1D1D9F7592F74BE86E3324F1 --lang=en-US --disable-pack-loading --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --log-severity=disable --product-version="ReaderServices/18.11.20036 Chrome/59.0.3071.15" --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553 --disable-accelerated-video-decode --disable-webrtc-hw-vp8-encoding --disable-gpu-compositing --service-request-channel-token=62F67FFA1D1D9F7592F74BE86E3324F1 --renderer-client-id=2 --mojo-platform-channel-handle=1288 --allow-no-sandbox-job /prefetch:1
RdrCEF.exe--type=renderer --primordial-pipe-token=56FFB4409D733A47B0EADB39D118F38C --lang=en-US --disable-pack-loading --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --log-severity=disable --product-version="ReaderServices/18.11.20036 Chrome/59.0.3071.15" --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553 --disable-accelerated-video-decode --disable-webrtc-hw-vp8-encoding --disable-gpu-compositing --service-request-channel-token=56FFB4409D733A47B0EADB39D118F38C --renderer-client-id=3 --mojo-platform-channel-handle=1352 --allow-no-sandbox-job /prefetch:1
iexplore.exe%TEMP%\A9R1wj6blo_1a8fwoi_19g.tmp\Invitation_Farewell_DE_EMB.html
iexplore.exeSCODEF:1380 CREDAT:275457 /prefetch:2