🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 381b0b3e95031c670b5e4132125a254e7c1e6bb3c0ae9c6a6916bbd2af2a9b02. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 11


Intelligence 11 IOCs YARA File information Comments

SHA256 hash: 381b0b3e95031c670b5e4132125a254e7c1e6bb3c0ae9c6a6916bbd2af2a9b02
SHA3-384 hash: ad05c477027bb07084664fbfa66e6bbb72042b357b5e99f116f1ef8fd929e3edfd529b27e131abbeee3c5267db827764
SHA1 hash: d1dc2a79fc5d037e604b68ea9856bb4d88f10e7b
MD5 hash: f1abd3aa14a2063b0e73808045d548f2
humanhash: xray-angel-carpet-artist
File name:PurchaseOrder_006231_Shanghuigou_20260605.pdf.js
Download: download sample
File size:818'996 bytes
First seen:2026-06-05 08:37:36 UTC
Last seen:2026-06-08 15:01:49 UTC
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 3072:zHxszvnwU8sCWJTYiTR4eU8pxRnKpUq2IKnWo4vhMU2oNtFpZivPPQtSjLWBpSya:+bnwU8sb
Threatray 26 similar samples on MalwareBazaar
TLSH T1F505F63DCD14412EE872CA19C99A046FF8C1465B622CEA4760D73B9FAF7288273D725D
TrID 66.6% (.TXT) Text - UTF-16 (LE) encoded (2000/1)
33.3% (.MP3) MP3 audio (1000/1)
Magika txt
Reporter abuse_ch
Tags:js

Intelligence


File Origin
# of uploads :
10
# of downloads :
141
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
conhost masquerade powershell repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-06-04T22:10:00Z UTC
Last seen:
2026-06-07T05:49:00Z UTC
Hits:
~1000
Detections:
PDM:Trojan.Win32.Generic HEUR:Trojan.Script.Generic
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.spyw.expl.evad
Score:
96 / 100
Signature
.NET source code contains potential unpacker
Creates a thread in another existing process (thread injection)
Creates an undocumented autostart registry key
Injects a PE file into a foreign processes
Powershell scriptblock execution from environment variable
Sigma detected: Suspicious Parent Double Extension File Execution
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Uses an obfuscated file name to hide its real file extension (double extension)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
WScript reads language and country specific registry keys (likely country aware script)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1923490 Sample: PurchaseOrder_006231_Shangh... Startdate: 05/06/2026 Architecture: WINDOWS Score: 96 39 cstaipas.pt 2->39 41 beacons.gcp.gvt2.com 2->41 43 beacons-handoff.gcp.gvt2.com 2->43 55 .NET source code contains potential unpacker 2->55 57 Uses an obfuscated file name to hide its real file extension (double extension) 2->57 59 Sigma detected: WScript or CScript Dropper 2->59 61 Sigma detected: Suspicious Parent Double Extension File Execution 2->61 9 wscript.exe 1 1 2->9         started        12 svchost.exe 1 2 2->12         started        signatures3 process4 dnsIp5 71 Windows Scripting host queries suspicious COM object (likely to drop second stage) 9->71 73 Suspicious execution chain found 9->73 75 WScript reads language and country specific registry keys (likely country aware script) 9->75 77 Powershell scriptblock execution from environment variable 9->77 15 conhost.exe 9->15         started        17 chrome.exe 2 9->17         started        53 127.0.0.1 unknown unknown 12->53 signatures6 process7 dnsIp8 20 powershell.exe 15 20 15->20         started        33 googlehosted.l.googleusercontent.com 142.250.217.1, 443, 49717 GOOGLE-GoogleLLCUS United States 17->33 35 www.google.com 142.251.154.119, 443, 49705, 49706 GOOGLE-GoogleLLCUS United States 17->35 37 5 other IPs or domains 17->37 process9 dnsIp10 45 cstaipas.pt 62.233.41.32, 443, 49692 WEBHSWEBSPLDAPT Portugal 20->45 47 5.101.81.161, 49693, 49694, 49734 AS-GLOBALTELEHOST-GTHostUS France 20->47 63 Creates an undocumented autostart registry key 20->63 65 Tries to steal Mail credentials (via file / registry access) 20->65 67 Tries to harvest and steal browser information (history, passwords, etc) 20->67 69 3 other signatures 20->69 24 chrome.exe 3 20->24         started        27 chrome.exe 2 20->27 injected 29 chrome.exe 2 20->29 injected 31 6 other processes 20->31 signatures11 process12 dnsIp13 49 192.168.2.8, 138, 443, 49512 unknown unknown 24->49 51 192.168.2.9 unknown unknown 24->51
Gathering data
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-06-05 03:40:23 UTC
File Type:
Text (JavaScript)
AV detection:
8 of 36 (22.22%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Command and Scripting Interpreter: PowerShell
Enumerates physical storage devices
Checks computer location settings
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments