🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 18a32a75629cfd7e3b2c30cd2fb2ce458171db591bdd3fd3750a7d2f92f02bf9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 18a32a75629cfd7e3b2c30cd2fb2ce458171db591bdd3fd3750a7d2f92f02bf9
SHA3-384 hash: 9714054ab63b2bd763b7fe25ed8d51a93cbfe47b4e8f32fd6bc5ab093b9822ee12f7b6b858b1f80f2535f71654dcdf08
SHA1 hash: 901ea6ae751030e8d5021d28bcae872bfcdb27c5
MD5 hash: 24e666163912f40cef43b0188f12eb7e
humanhash: network-yankee-hamper-nitrogen
File name:Order_399201.xls.js
Download: download sample
File size:556'938 bytes
First seen:2026-08-18 19:15:41 UTC
Last seen:2026-08-18 19:15:43 UTC
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 6144:UM35fxkmEJw1yPQyakNi7rjxyAtGu9tkh8z0J4mY:/JfrEJwMfwFJtDBk4mY
TLSH T1F7C4752DF2A4C23558520962D2F1A1038D3DAEAE1F5F12233EBE56DFD3A6D542D138C6
TrID 66.6% (.TXT) Text - UTF-16 (LE) encoded (2000/1)
33.3% (.MP3) MP3 audio (1000/1)
Magika txt
Reporter TomU
Tags:js

Intelligence


File Origin
# of uploads :
2
# of downloads :
151
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
aes base64 base64 base64 conhost crypto downloader evasive lolbin masquerade obfuscated overlay persistence powershell repaired wscript
Gathering data
Threat name:
Win32.Trojan.Malgent
Status:
Malicious
First seen:
2026-08-18 00:44:14 UTC
File Type:
Text (JavaScript)
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
execution persistence
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Command and Scripting Interpreter: JavaScript
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Java Script (JS) js 18a32a75629cfd7e3b2c30cd2fb2ce458171db591bdd3fd3750a7d2f92f02bf9

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments