MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 26b40edcb6058e198db20eeeb6c02cb4a0d54c89bce38361f1ea7bedc4e60ebc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: 26b40edcb6058e198db20eeeb6c02cb4a0d54c89bce38361f1ea7bedc4e60ebc
SHA3-384 hash: 9ec6c34343213f96b21909249c7d72ddb270a7cf36597fc11ae0d05748b790ef3439a35d99a21a1cbca2770875897e05
SHA1 hash: b5c7a0746ad740b66cb4c9f654771c9f4270acac
MD5 hash: 9a503f295d04ba70155935f6663683ac
humanhash: indigo-delaware-august-butter
File name:NEW PO 367328911.js
Download: download sample
File size:493'668 bytes
First seen:2026-05-04 07:53:00 UTC
Last seen:2026-05-04 12:25:53 UTC
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 12288:3MgoE7Gw5Osp6lV0aa6LRpjbvDAh2oo+hCUYurv+hRQKkiMHAJkPie/K:8v1sg9PUWiye5y
Threatray 338 similar samples on MalwareBazaar
TLSH T1A1A4BE24ABFA1019F1B3DF54AEF56452A83FBB623A0ED45D1190038E0632E45EDA573F
TrID 66.6% (.TXT) Text - UTF-16 (LE) encoded (2000/1)
33.3% (.MP3) MP3 audio (1000/1)
Magika txt
Reporter jahlives
Tags:exe-in-archive js spamtrap

Intelligence


File Origin
# of uploads :
3
# of downloads :
143
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
aes base64 conhost crypto encrypted obfuscated overlay powershell repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-05-03T21:02:00Z UTC
Last seen:
2026-05-06T06:39:00Z UTC
Hits:
~1000
Detections:
Trojan.MSIL.Agent.sb PDM:Trojan.Win32.Generic HEUR:Trojan-Downloader.Script.Generic HEUR:Trojan.Script.Generic
Verdict:
inconclusive
YARA:
1 match(es)
Threat name:
Script-JS.Trojan.Cryxos
Status:
Malicious
First seen:
2026-05-03 23:57:43 UTC
File Type:
Text (JavaScript)
AV detection:
11 of 38 (28.95%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
collection discovery execution persistence
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
Browser Information Discovery
Command and Scripting Interpreter: JavaScript
Command and Scripting Interpreter: PowerShell
Enumerates physical storage devices
System Time Discovery
Drops file in Windows directory
Accesses Microsoft Outlook profiles
Checks computer location settings
Registers new Windows logon scripts automatically executed at logon.
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments