MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 31b43a3f7c15b25f7066983d9d3fb0361681de5c4d8bf0c2e5f64a1ae91e7cfa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: 31b43a3f7c15b25f7066983d9d3fb0361681de5c4d8bf0c2e5f64a1ae91e7cfa
SHA3-384 hash: 51cc4980c6752b05013379a835ea7669bfba5aec8bd89b7048d9386938f30522dc5c2419c74d81e8a3d2e97448d788c0
SHA1 hash: 7146a0e270baddd2323691ceedd2ffdff2b72745
MD5 hash: da245985dccd8d0d31aa0d8539462d22
humanhash: alpha-nebraska-triple-delta
File name:31b43a3f7c15b25f7066983d9d3fb0361681de5c4d8bf0c2e5f64a1ae91e7cfa.hta
Download: download sample
File size:1'330 bytes
First seen:2026-05-27 00:19:14 UTC
Last seen:2026-05-27 09:11:40 UTC
File type:HTML Application (hta) hta
MIME type:text/html
ssdeep 24:k42cLLhJwYgTjMTGqoLldp6XlH0RY5lTlqh9TAKUZFBKG422UClESjLBKuYjxfSa:k4lL7wbTzBMXva4Znno9y8hNu
TLSH T13E2144456A6283D87DB12A64C27E9106B0D6821BA5C0FD58F7DCA112BF21653EF0A1F2
Magika html
Reporter johnk3r
Tags:atualizanavegador-online hta latam

Intelligence


File Origin
# of uploads :
2
# of downloads :
169
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Result
Verdict:
Malicious
File Type:
HTA File - Malicious
Behaviour
BlacklistAPI detected
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
obfuscated zero-day
Verdict:
Malicious
File Type:
hta
First seen:
2026-05-26T14:53:00Z UTC
Last seen:
2026-05-27T00:42:00Z UTC
Hits:
~100
Detections:
Trojan-Downloader.JS.SLoad.sb HEUR:Trojan-Downloader.HTA.SLoad.gen
Result
Threat name:
n/a
Detection:
malicious
Classification:
spre.troj.spyw.expl.evad.mine
Score:
100 / 100
Signature
Allocates memory in foreign processes
Clears Internet Explorer cache and cookies (likely to cover tracks)
Command shell drops VBS files
Found strings related to Crypto-Mining
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Obfuscated command line found
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious MSHTA Child Process
Sigma detected: Windows Shell/Scripting Application File Write to Suspicious Folder
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Suspicious execution chain found
System process connects to network (likely due to code injection or exploit)
Tries to access browser extension known for cryptocurrency wallets
Unusual module load detection (module proxying)
Uses cmd line tools excessively to alter registry or file data
Uses ping.exe to check the status of other devices and networks
Uses ping.exe to sleep
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
WScript reads language and country specific registry keys (likely country aware script)
Yara detected VBS Downloader Generic
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1918994 Sample: eV6am2Kf42.hta Startdate: 27/05/2026 Architecture: WINDOWS Score: 100 95 atualizanavegador.online 2->95 97 remoto.ddins.click 2->97 99 5 other IPs or domains 2->99 133 Suricata IDS alerts for network traffic 2->133 135 Yara detected VBS Downloader Generic 2->135 137 Sigma detected: Suspicious MSHTA Child Process 2->137 139 4 other signatures 2->139 10 mshta.exe 1 15 2->10         started        14 fscnneed.exe 2->14         started        17 fscnneed.exe 2->17         started        signatures3 process4 dnsIp5 117 atualizanavegador.online 172.67.211.71, 443, 49712, 49716 CLOUDFLARENET-CloudflareIncUS Canada 10->117 161 Obfuscated command line found 10->161 163 Clears Internet Explorer cache and cookies (likely to cover tracks) 10->163 19 cmd.exe 1 10->19         started        21 cmd.exe 2 10->21         started        25 cmd.exe 1 10->25         started        31 4 other processes 10->31 91 C:\Users\user\AppData\Local\...\~tmp3022.tmp, PE32 14->91 dropped 165 Uses cmd line tools excessively to alter registry or file data 14->165 167 Writes to foreign memory regions 14->167 169 Allocates memory in foreign processes 14->169 27 attrib.exe 14->27         started        93 C:\Users\user\AppData\Local\...\~tmp9377.tmp, PE32 17->93 dropped 171 Injects a PE file into a foreign processes 17->171 29 attrib.exe 17->29         started        file6 signatures7 process8 file9 33 wscript.exe 25 19->33         started        37 conhost.exe 19->37         started        83 C:\Users\Public\QPJD94.vbs, ASCII 21->83 dropped 141 Uses ping.exe to sleep 21->141 143 Command shell drops VBS files 21->143 145 Uses ping.exe to check the status of other devices and networks 21->145 39 conhost.exe 21->39         started        41 PING.EXE 1 25->41         started        44 conhost.exe 25->44         started        147 Tries to access browser extension known for cryptocurrency wallets 27->147 46 msedgewebview2.exe 27->46         started        48 msedgewebview2.exe 27->48         started        50 2 other processes 29->50 149 Clears Internet Explorer cache and cookies (likely to cover tracks) 31->149 52 4 other processes 31->52 signatures10 process11 dnsIp12 81 C:\Users\user\AppData\...\fscnneed.exe, PE32 33->81 dropped 123 System process connects to network (likely due to code injection or exploit) 33->123 125 Windows Scripting host queries suspicious COM object (likely to drop second stage) 33->125 127 Suspicious execution chain found 33->127 131 2 other signatures 33->131 54 fscnneed.exe 2 4 33->54         started        59 rundll32.exe 33->59         started        115 127.0.0.1 unknown unknown 41->115 129 Found strings related to Crypto-Mining 46->129 61 msedgewebview2.exe 46->61         started        63 msedgewebview2.exe 46->63         started        71 3 other processes 46->71 65 msedgewebview2.exe 48->65         started        67 msedgewebview2.exe 48->67         started        69 msedgewebview2.exe 48->69         started        73 2 other processes 48->73 file13 signatures14 process15 dnsIp16 101 remoto.ddins.click 198.199.75.154, 443, 49727, 49733 DIGITALOCEAN-ASN-DigitalOceanLLCUS United States 54->101 103 api.cloudflare.com 104.19.192.29, 443, 49726, 49731 CLOUDFLARENET-CloudflareIncUS Canada 54->103 85 C:\Users\user\AppData\...\turbojpeg.dll, PE32 54->85 dropped 87 C:\Users\user\AppData\...\WebView2Loader.dll, PE32 54->87 dropped 89 C:\Users\user\AppData\Local\...\~tmp1580.tmp, PE32 54->89 dropped 151 Uses cmd line tools excessively to alter registry or file data 54->151 153 Writes to foreign memory regions 54->153 155 Allocates memory in foreign processes 54->155 157 Injects a PE file into a foreign processes 54->157 75 attrib.exe 7 54->75         started        159 Clears Internet Explorer cache and cookies (likely to cover tracks) 59->159 79 rundll32.exe 59->79         started        105 150.171.27.11, 443, 49792 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS United States 61->105 107 172.64.41.3, 443, 49744, 49745 CLOUDFLARENET-CloudflareIncUS Canada 61->107 109 ln-0007.ln-msedge.net 150.171.22.17, 443, 49736, 49737 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS United States 65->109 111 150.171.28.11, 443, 49793 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS United States 65->111 113 chrome.cloudflare-dns.com 162.159.61.3, 443, 49742, 49743 CLOUDFLARENET-CloudflareIncUS Canada 65->113 file17 signatures18 process19 dnsIp20 119 ip-api.com 208.95.112.1, 49730, 49735, 49747 TUT-AS-TotalUptimeTechnologiesLLCUS United States 75->119 121 api.ipify.org 172.67.74.152, 443, 49728, 49734 CLOUDFLARENET-CloudflareIncUS Canada 75->121 173 Tries to access browser extension known for cryptocurrency wallets 75->173 175 Unusual module load detection (module proxying) 75->175 signatures21
Gathering data
Verdict:
Malicious
Threat:
Trojan-Downloader.JS.SLoad
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-05-26 21:22:04 UTC
File Type:
Text (HTML)
Extracted files:
1
AV detection:
7 of 24 (29.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery
Behaviour
System Location Discovery: System Language Discovery
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MalScript_Tricks
Author:@bartblaze
Description:Identifies tricks often seen in malicious scripts such as moving the window off-screen or resizing it to zero.
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments