🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2d47e303a6c278097ead4e6a754edf1a860ed7587f37e228bcea59eb7092f7a7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 2d47e303a6c278097ead4e6a754edf1a860ed7587f37e228bcea59eb7092f7a7
SHA3-384 hash: 0e9324927e44f04504054b6bd86dac95d72966c41f7ac2fa8e67f55ef32f06bc03c0dfe3449cd854cd75820903d51b24
SHA1 hash: 1b4e6d941ee0a08eddb5045f7dc50544ed8bc894
MD5 hash: 6604addaba8902252a2a6a45667c3282
humanhash: november-arkansas-maryland-green
File name:shellSession.js
Download: download sample
File size:4'168 bytes
First seen:2026-10-01 10:39:16 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/x-c++
ssdeep 96:ANccZYY6uN5wRmRuWGN3DjgaQ39dcxDmoX9v:A6cZDZNaRmRtGNPg5kNNv
TLSH T1D081CD9B37FA463C58B3E6111E5F5401A77A800F369DDDD879EC6640EFB4C2882A1B38
Magika javascript
Reporter emilstahl
Tags:ChainScript EtherHiding js NodeJS-RAT polygon

Intelligence


File Origin
# of uploads :
1
# of downloads :
113
Origin country :
DK DK
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-10-01T10:49:00Z UTC
Last seen:
2026-10-01T10:53:00Z UTC
Hits:
~10
Verdict:
Malware
YARA:
1 match(es)
Tags:
DeObfuscated PowerShell T1027 T1059.001
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Command and Scripting Interpreter: JavaScript
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments