MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 1a1787c8836218573101aee212eec3ce846dd48d682df416d249ea4af5d4812c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 8
| SHA256 hash: | 1a1787c8836218573101aee212eec3ce846dd48d682df416d249ea4af5d4812c |
|---|---|
| SHA3-384 hash: | 860fdadaa665435456bd8902f701634881fee65cdd2d8b04b7f2a957050b6c5ac1cee7c5552b3fd54fe49a790c41c5f5 |
| SHA1 hash: | 6bac672f70a4719a416abe9a641a87517786c6c4 |
| MD5 hash: | 2c4acc0fd3fe208e0b4a81e375df9ee5 |
| humanhash: | vermont-mississippi-blossom-quiet |
| File name: | fuck_niggers_28.hta |
| Download: | download sample |
| File size: | 497 bytes |
| First seen: | 2025-05-18 11:33:08 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | text/html |
| ssdeep | 12:kxvsCk9cE3Mo1T/XU5QirJNVydNR2MWzXaL4nYI:kbxmT/k5Qeydrp/BI |
| TLSH | T1E1F054EB0CD7DECDF1D10C45CE8542D4DC8A85817054F41984E84C5CB43439FDD49036 |
| Magika | txt |
| Reporter | |
| Tags: | hta |
Intelligence
File Origin
# of uploads :
1
# of downloads :
70
Origin country :
DEVendor Threat Intelligence
Detection(s):
Verdict:
Malicious
Score:
70%
Tags:
blic sage hype
Result
Verdict:
Malicious
File Type:
HTA File - Malicious
Payload URLs
URL
File name
https://daftar.site/SU3D/fuck_niggers_28.hta?ch=1&js=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJKb2tlbiIsImV4cCI6MTc0NzU3NDgyOCwiaWF0IjoxNzQ3NTY3NjI4LCJpc3MiOiJKb2tlbiIsImpzIjoxLCJqdGkiOiIzMTA5bXZ0ZmphbWZyaXZuYTgxMjd1MDMiLCJuYmYiOjE3NDc1Njc2MjgsInRzIjoxNzQ3NTY3NjI4MTI5MDMxfQ.0wkY55wOgahdnMu7lMo82DazGB98iVElSKCcwkm4bRQ&sid=0875d467-33db-11f0-948f-416bd8df8d10');
HTA File
Verdict:
Malicious
Threat level:
10/10
Confidence:
100%
Tags:
base64 evasive fingerprint obfuscated
Verdict:
Malicious
Labled as:
JS/Redirector.QNO trojan
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Antivirus detection for URL or domain
Behaviour
Behavior Graph:
Score:
1%
Verdict:
Benign
File Type:
SCRIPT
Threat name:
Script-JS.Trojan.Redirector
Status:
Malicious
First seen:
2025-05-18 11:34:13 UTC
File Type:
Text (HTML)
Extracted files:
1
AV detection:
7 of 24 (29.17%)
Threat level:
5/5
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
6/10
Tags:
defense_evasion discovery trojan
Behaviour
Modifies Internet Explorer settings
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Checks whether UAC is enabled
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
hta 1a1787c8836218573101aee212eec3ce846dd48d682df416d249ea4af5d4812c
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.