MalwareBazaar Database

This page shows some basic information the YARA rule CHM_File_Executes_JS_Via_PowerShell including corresponding malware samples.

Database Entry


YARA Rule:CHM_File_Executes_JS_Via_PowerShell
Author:daniyyell
Description:Detects a Microsoft Compiled HTML Help (CHM) file that executes embedded JavaScript to launch a messagebox via PowerShell
Firstseen:2024-09-13 11:30:30 UTC
Lastseen:2025-11-25 07:33:34 UTC
Sightings:138

Malware Samples


The table below shows all malware samples that matching this particular YARA rule (max 1000).

Firstseen (UTC)SHA256 hashTagsSignatureReporter