MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3cb6f47bafad0d907e8ce41c4b4fdd40477c55a0ca1c6f44dec0b15084c57831. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SmartLoader


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 3cb6f47bafad0d907e8ce41c4b4fdd40477c55a0ca1c6f44dec0b15084c57831
SHA3-384 hash: f80ec50bbb054a45eb4926bdefbcc8c7a86eee1a4410dbfa3d5eabbbef4c47962330394529ea2a006876a60a6a7bb2ab
SHA1 hash: e94da1ffc1ac7af135aebe25075d8a41f2ed6c12
MD5 hash: 0461b36a91e01dc3e03c6ba0f3a53c75
humanhash: nevada-moon-diet-winter
File name:libs.txt
Download: download sample
Signature SmartLoader
File size:244'682 bytes
First seen:2025-03-16 12:28:16 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 3072:8rCAwuFRKS3/t25FyzM3JbwqSVNdVprDj8BBCs5HBHLtE7am:rA8UlW8zM390NdfrDo7CsNBrtY/
TLSH T1BF3417C0EAB019D1A7F949AECE718D30233D2E73E946688E362DF6F0255158E9519C3F
Magika javascript
Reporter tcains1
Tags:js lua SmartLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
634
Origin country :
US US
Vendor Threat Intelligence
Verdict:
Malicious
Score:
96.5%
Tags:
virus agent
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
infostealer masquerade obfuscated
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
60 / 100
Signature
Multi AV Scanner detection for submitted file
Sigma detected: Cscript/Wscript Uncommon Script Extension Execution
Sigma detected: WScript or CScript Dropper
Uses an obfuscated file name to hide its real file extension (double extension)
Behaviour
Behavior Graph:
Threat name:
Script-Lua.Trojan.Heuristic
Status:
Malicious
First seen:
2025-03-10 23:42:16 UTC
File Type:
Text (Lua)
AV detection:
10 of 36 (27.78%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Command and Scripting Interpreter: JavaScript
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

SmartLoader

Java Script (JS) js 3cb6f47bafad0d907e8ce41c4b4fdd40477c55a0ca1c6f44dec0b15084c57831

(this sample)

  
Delivery method
Distributed via web download

Comments