MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 414f2ad91a23512aa4f55c15fb7f06ace0e178a3df84d5dd6fbe87b47fc8d548. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 11


Intelligence 11 IOCs YARA File information Comments

SHA256 hash: 414f2ad91a23512aa4f55c15fb7f06ace0e178a3df84d5dd6fbe87b47fc8d548
SHA3-384 hash: dbf6cc27e3ad0117d5edb25b166d73f05fdb71895555e0d2b443a59a292f5abe1326f89ea429e11e122bd25c4e4138f1
SHA1 hash: a2f4f4f4142727e6b8dcd7bc093865e533e18b77
MD5 hash: b47ba9b44f6559e1d9e26e38f9cf8771
humanhash: salami-early-michigan-six
File name:Factura pendiente de pago.js
Download: download sample
File size:44'464 bytes
First seen:2026-06-10 13:05:21 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 384:1F8sS+1EhZbUvWuPekj0R+52DaG232YxjbmII5CVn:1F81rhKeoe2ZG232iKI1
TLSH T1A6136915769FCA1422A247890AAF07B54B6F795F1FBF409A004DEEC98FD35229C473B2
TrID 66.6% (.TXT) Text - UTF-16 (LE) encoded (2000/1)
33.3% (.MP3) MP3 audio (1000/1)
Magika vba
Reporter threatcat_ch
Tags:js

Intelligence


File Origin
# of uploads :
1
# of downloads :
144
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
93.3%
Tags:
shell sage blic
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
base64 fingerprint ipconfig ipconfig masquerade obfuscated powershell powershell repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-06-10T06:48:00Z UTC
Last seen:
2026-06-12T11:44:00Z UTC
Hits:
~1000
Detections:
PDM:Trojan.Win32.Generic Trojan.JS.SAgent.sb HEUR:Trojan.Script.Generic HEUR:Trojan.PowerShell.Generic
Result
Threat name:
n/a
Detection:
malicious
Classification:
expl.evad
Score:
100 / 100
Signature
Bypasses PowerShell execution policy
Found suspicious powershell code related to unpacking or dynamic code loading
Joe Sandbox ML detected suspicious sample
JScript performs obfuscated calls to suspicious functions
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sigma detected: Base64 Encoded PowerShell Command Detected
Sigma detected: Execution of Powershell Script in Public Folder
Sigma detected: Potential PowerShell Command Line Obfuscation
Sigma detected: PowerShell Base64 Encoded FromBase64String Cmdlet
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Windows Shell/Scripting Application File Write to Suspicious Folder
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Uses ipconfig to lookup or modify the Windows network settings
Windows Scripting host queries suspicious COM object (likely to drop second stage)
WScript reads language and country specific registry keys (likely country aware script)
Wscript starts Powershell (via cmd or directly)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1925897 Sample: Factura pendiente de pago.js Startdate: 10/06/2026 Architecture: WINDOWS Score: 100 32 andrefelipedonascime1778799406970.2241107.meusitehostgator.com.br 2->32 36 Malicious sample detected (through community Yara rule) 2->36 38 Multi AV Scanner detection for submitted file 2->38 40 Sigma detected: PowerShell Base64 Encoded FromBase64String Cmdlet 2->40 42 7 other signatures 2->42 9 wscript.exe 1 1 2->9         started        signatures3 process4 signatures5 44 JScript performs obfuscated calls to suspicious functions 9->44 46 Suspicious powershell command line found 9->46 48 Wscript starts Powershell (via cmd or directly) 9->48 50 4 other signatures 9->50 12 powershell.exe 17 9->12         started        process6 file7 28 C:\Users\Public\cnwgf.ps1, Unicode 12->28 dropped 52 Uses ipconfig to lookup or modify the Windows network settings 12->52 54 Found suspicious powershell code related to unpacking or dynamic code loading 12->54 16 powershell.exe 38 12->16         started        20 conhost.exe 12->20         started        signatures8 process9 dnsIp10 30 andrefelipedonascime1778799406970.2241107.meusitehostgator.com.br 172.64.145.200, 443, 49722 CLOUDFLARENET-CloudflareIncUS Canada 16->30 34 Loading BitLocker PowerShell Module 16->34 22 powershell.exe 9 16->22         started        24 WmiPrvSE.exe 16->24         started        26 ipconfig.exe 1 16->26         started        signatures11 process12
Gathering data
Threat name:
Win32.Downloader.Nemucod
Status:
Malicious
First seen:
2026-06-10 13:00:19 UTC
File Type:
Text (JavaScript)
AV detection:
12 of 24 (50.00%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
execution
Behaviour
Gathers network information
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Command and Scripting Interpreter: PowerShell
Checks computer location settings
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Java Script (JS) js 414f2ad91a23512aa4f55c15fb7f06ace0e178a3df84d5dd6fbe87b47fc8d548

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments