MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3e120cc23a568678151b2bc258291511e3fa0b5983f7cf301aac95e4c0d2a44c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LxBaseRAT


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: 3e120cc23a568678151b2bc258291511e3fa0b5983f7cf301aac95e4c0d2a44c
SHA3-384 hash: bdc567dd77807a3abe2727638fe9f1f042f4852adb0f1b04d67a957f413ce7b28199d30fb3fab0f920a31ef47ecf5807
SHA1 hash: f1dfc55c1849580ea833cc7af561cb404ae3bccc
MD5 hash: 44ab116032e2cfc02a7a30ff23480556
humanhash: kentucky-montana-saturn-eleven
File name:Заказ_17954103024072026_Azotny_Zavod_LLP.js
Download: download sample
Signature LxBaseRAT
File size:1'916'389 bytes
First seen:2026-07-24 12:47:16 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 24576:u/rLfjeWObseQ2ef8yHFqs6X8JNQiyPE9a1QIWw6q4eq7:LuB2WHu8giy846q1A
TLSH T1E7959EE83B90D799993E4FE199B71D9AA1F20D839500DD8CC97937697F28306CEB8D01
Magika javascript
Reporter TomU
Tags:js LxBaseRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
152
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
encrypted evasive lolbin obfuscated persistence repaired wscript
Verdict:
Suspicious
Labled as:
SVM:TrojanDownloader/JS.MalBehav.gen
Verdict:
Malicious
File Type:
js
First seen:
2026-07-24T05:34:00Z UTC
Last seen:
2026-07-26T09:17:00Z UTC
Hits:
~1000
Gathering data
Result
Malware family:
lxbaserat
Score:
  10/10
Tags:
family:lxbaserat botnet:july-24-2026 campaign:f3b65f6eafa54b53a38fb207ea5d6a92 collection execution persistence rat upx
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
outlook_office_path
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Executes a VBScript file via the Windows Script Host.
Suspicious use of SetThreadContext
UPX packed file
Accesses Microsoft Outlook profiles
Looks up external IP address via web service
Checks computer location settings
Loads dropped DLL
Command and Scripting Interpreter: PowerShell
Family: LxBaseRAT
Malware Config
C2 Extraction:
lxrrxl.ydns.eu:4521
Malware family:
LXKeylogger
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_obfuscated_JS_obfuscatorio
Author:@imp0rtp3
Description:Detect JS obfuscation done by the js obfuscator (often malicious)
Reference:https://obfuscator.io
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

LxBaseRAT

Java Script (JS) js 3e120cc23a568678151b2bc258291511e3fa0b5983f7cf301aac95e4c0d2a44c

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments