MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1429c59a338928e0934c019be499ca5325399b640faa5c4bd9fbb87efc4c970f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 1429c59a338928e0934c019be499ca5325399b640faa5c4bd9fbb87efc4c970f
SHA3-384 hash: fdbdbcce0607877a39898325853c62d77f4948cea266c6f65c5c8356c570f797de9d37332da2d7ca8ecd22dcdd20a1d8
SHA1 hash: 8fce3399d027a683b1f3ebed018540ff8e5ca4af
MD5 hash: e9638bb06b2cad78c026a62af8c7ed4c
humanhash: bacon-october-fruit-social
File name:Comprobante de Pago.pdf.js
Download: download sample
File size:53'921 bytes
First seen:2026-08-10 17:41:13 UTC
Last seen:2026-08-10 17:49:12 UTC
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 192:c7FqhnIhELBoxCjMSUwaglu5RF9QMW5w5MpiLp6P0TsVfcXsDwwK/oPPMctKd+Aq:wycIK/o/r
TLSH T17633195ECDA369706EFE5DC587893521E132FDBFE64B1F75288CDEA104AEA318831910
Magika javascript
Reporter James_inthe_box
Tags:exe js

Intelligence


File Origin
# of uploads :
2
# of downloads :
148
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm base64 evasive fingerprint masquerade obfuscated overlay powershell repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-08-10T13:59:00Z UTC
Last seen:
2026-08-10T14:40:00Z UTC
Hits:
~100
Gathering data
Result
Malware family:
n/a
Score:
  10/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Command and Scripting Interpreter: JavaScript
Command and Scripting Interpreter: PowerShell
Badlisted process makes network request
Process spawned unexpected child process
Malware Config
Dropper Extraction:
https://muddy-sound-e0cd.nodetectonn.workers.dev/hyQIq
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments