🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 092a448459c06da52ca187b4fddf4bc53614db451a62d0b7dbaacd9c27089aba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 092a448459c06da52ca187b4fddf4bc53614db451a62d0b7dbaacd9c27089aba
SHA3-384 hash: 5273f719b41bfbb2e270217f0f350dec968a5ac31d3ea22b75c7712a9765a329b6d2655b3fd885595919d166cf5c1557
SHA1 hash: 16ce66cc88927812d863fb3f0f17a9d9c4279a9c
MD5 hash: b5c312c3471b0847e4dff71c13cd4f11
humanhash: potato-batman-oklahoma-dakota
File name:orden.js
Download: download sample
File size:3'140'815 bytes
First seen:2026-09-04 16:03:04 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 12288:4XVv2cjLb/GpsUfeW1wwkRm1VSSxQo+xWf4qr52Adboo5d0XkXPbxBhoiNJCrG1U:i
TLSH T170E5EE197244912ADC63736330BF134BA85BAE3C8337030E7D66DE84D2694EFDDA9166
Magika javascript
Reporter abuse_ch
Tags:js

Intelligence


File Origin
# of uploads :
1
# of downloads :
161
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cmd conhost conhost.exe evasive lolbin obfuscated powershell powershell.exe repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-09-04T12:12:00Z UTC
Last seen:
2026-09-04T13:04:00Z UTC
Hits:
~100
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad.expl
Score:
68 / 100
Signature
JavaScript file contains suspicious strings
Malicious sample detected (through community Yara rule)
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Windows Scripting host queries suspicious COM object (likely to drop second stage)
WScript reads language and country specific registry keys (likely country aware script)
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1968762 Sample: orden.js Startdate: 04/09/2026 Architecture: WINDOWS Score: 68 24 Malicious sample detected (through community Yara rule) 2->24 26 Sigma detected: WScript or CScript Dropper 2->26 28 JavaScript file contains suspicious strings 2->28 8 wscript.exe 1 1 2->8         started        11 svchost.exe 1 1 2->11         started        process3 dnsIp4 30 Windows Scripting host queries suspicious COM object (likely to drop second stage) 8->30 32 Suspicious execution chain found 8->32 34 WScript reads language and country specific registry keys (likely country aware script) 8->34 14 conhost.exe 8->14         started        22 127.0.0.1 unknown unknown 11->22 signatures5 process6 process7 16 cmd.exe 1 14->16         started        process8 18 powershell.exe 16 16->18         started        20 cmd.exe 1 16->20         started       
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
PowerShell T1059.001
Result
Malware family:
n/a
Score:
  7/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Command and Scripting Interpreter: PowerShell
Enumerates physical storage devices
Executes a command shell one-liner
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments