🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0930b4fc55767e86d3ca9f4b6a17db64ad1b1d23b6a9f358d78b06bd2216b8b9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Kimsuky


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 0930b4fc55767e86d3ca9f4b6a17db64ad1b1d23b6a9f358d78b06bd2216b8b9
SHA3-384 hash: 10038b1b832709f368f78c1bb6dfec06a2e16439223bb2879dee5d610d297ceafa69a8eaa293b372a211887875f61314
SHA1 hash: 72aebff80bab549940404553868307aadfbce47d
MD5 hash: 5fca1117c0e5ee6de3c169eebc903227
humanhash: oxygen-avocado-eighteen-spring
File name:83972.js
Download: download sample
Signature Kimsuky
File size:1'571 bytes
First seen:2025-02-09 09:10:17 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 24:2UNvy0XTuGoOAS926v3ARjD9hsfRbIm4//mav7i4uaWHk/AGYq8Lj3dFEAXahC:3Nvy7GFAcZvO54Rb5UlTi4WHEAGY2r0
TLSH T11E3153853784A134936D1EA38CAF588EEE35BD5215098D20EC86DBC02894D7DC0FBFA8
Magika javascript
Reporter JAMESWT_WT
Tags:APT43 forceCopy js Kimsuky

Intelligence


File Origin
# of uploads :
1
# of downloads :
505
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Malicious
Score:
91.7%
Tags:
virus
Result
Threat name:
n/a
Detection:
malicious
Classification:
expl.evad
Score:
72 / 100
Signature
Bypasses PowerShell execution policy
JScript performs obfuscated calls to suspicious functions
Sigma detected: Suspicious PowerShell Parameter Substring
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript starts Powershell (via cmd or directly)
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2025-02-09 09:08:10 UTC
File Type:
Text (JavaScript)
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Command and Scripting Interpreter: PowerShell
Enumerates physical storage devices
System Location Discovery: System Language Discovery
System Network Configuration Discovery: Internet Connection Discovery
Checks computer location settings
Downloads MZ/PE file
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments