🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5e76b879acca4e39ce6e07237cd81979c738dd4f89e834d1ebe7e33405b10737. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 5e76b879acca4e39ce6e07237cd81979c738dd4f89e834d1ebe7e33405b10737
SHA3-384 hash: 85bf5e0b45911988aeefae23aeb954f8120db89a60dc564cb1fe4838846d233db618b9d417e0f9318cec0b1d75258cb6
SHA1 hash: dd2bc8049e05c45f1f967214cd100e8b4f55e3ad
MD5 hash: 7debd912213a61a0b7f3bcf749aeae02
humanhash: wisconsin-equal-utah-hotel
File name:Demanda_Ordinaria_Responsabilidad_Civil_Extracontractual_NUM50057.wsf
Download: download sample
File size:18'389 bytes
First seen:2026-09-04 20:09:43 UTC
Last seen:Never
File type:
MIME type:text/xml
ssdeep 384:1PhPy8zENvhkjxKGkGhhvZB21Hl9lOW027orZTe3JFDVyBix46GpDhJ0r:1Phz25kjxKGNz21FDlY0FDcBu468Jo
TLSH T16782265303851B79F68D0EC8898A356B21F2D567BD280659EBB36DEBBC3F9845030736
Magika html
Reporter cypherpunk472
Tags:cryxos javascript wsf wsh


Avatar
cypherpunk472
xhtml -> password protectec zip -> wsf

Intelligence


File Origin
# of uploads :
1
# of downloads :
35
Origin country :
CO CO
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
encrypted evasive
Verdict:
Malware
YARA:
3 match(es)
Tags:
Html Javascript T1059.007 WSF File
Threat name:
Script-JS.Trojan.Cryxos
Status:
Malicious
First seen:
2026-09-04 20:10:27 UTC
File Type:
Text (XML)
Extracted files:
1
AV detection:
3 of 36 (8.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
execution
Behaviour
Executes a VBScript file via the Windows Script Host.
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

5e76b879acca4e39ce6e07237cd81979c738dd4f89e834d1ebe7e33405b10737

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments