MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2e854a9dd551ec84684aa6e2fcab3782aed01059ee68aa97a2129ee16175a62c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 2e854a9dd551ec84684aa6e2fcab3782aed01059ee68aa97a2129ee16175a62c
SHA3-384 hash: 282177ffaf342054a91877e1ac353ff9b1f009d5a436fcfac8af783ca78082fca5d8eaf2b352722610638abc18b805e9
SHA1 hash: efc7ba3f3fdea47f2be31e7a345728aebc3e0c14
MD5 hash: d31b844e6c3d3a0515dc014c25c66549
humanhash: mockingbird-mars-mirror-fruit
File name:Directrices de políticas para empleados_2026.pdf.jse
Download: download sample
File size:44'492 bytes
First seen:2026-07-23 06:08:37 UTC
Last seen:Never
File type:JScript (JSE) jse
MIME type:text/plain
ssdeep 768:exS4PgR7FwiHqZIMdoYg9mGmNgYNdAV2Kynf0:exSqgvwiKZxofmGJ0dYXynf0
TLSH T13A13458D3EC2B4B04763A43B6D2FB196F26F8C81B2C8D544E71AF458F814704D6E5B68
Magika javascript
Reporter lowmal3
Tags:jse

Intelligence


File Origin
# of uploads :
1
# of downloads :
38
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
js
First seen:
2026-07-07T14:35:00Z UTC
Last seen:
2026-07-24T21:36:00Z UTC
Hits:
~1000
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
80 / 100
Signature
Found potential dummy code loops (likely to delay analysis)
JavaScript source code contains functionality to generate code involving a shell, file or stream
JavaScript source code contains functionality to generate code involving HTTP requests or file downloads
Multi AV Scanner detection for submitted file
Potential obfuscated javascript found
Sigma detected: WScript or CScript Dropper
Uses an obfuscated file name to hide its real file extension (double extension)
Yara detected AntiDebug via ReDoS RegEx
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Malgent
Status:
Malicious
First seen:
2026-07-07 18:32:41 UTC
File Type:
Text (JavaScript)
AV detection:
11 of 38 (28.95%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
execution
Behaviour
Command and Scripting Interpreter: JavaScript
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments