🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 64c52a52d64ea44a8b8e1a9fa367e37a9940f847fcd142182711b1b862efb8a2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 64c52a52d64ea44a8b8e1a9fa367e37a9940f847fcd142182711b1b862efb8a2
SHA3-384 hash: 6030807729c673d42407064e4e15292644c9bab52be99b9b84df57efd7cc887f8669f4ce3b2479225e559e61a80dd5b7
SHA1 hash: 72f892333cb309c044be46fcf75de2be90988da6
MD5 hash: 6a406568803f08e822270ea628727b0b
humanhash: pip-texas-bakerloo-oscar
File name:tld.min.mobile.js
Download: download sample
File size:143'650 bytes
First seen:2026-09-05 11:05:03 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/x-c
ssdeep 1536:knDTjitRV0MXpb3AX1rxGsv31zgdKkWx14lHoRq:knfjitR+MqFrb1MdRNx
TLSH T1A6E330DD8D086B539667F8B07212701FE5E4FD9ED6DC07C868A3B99898C8558E2DCBC0
Magika javascript
Reporter KabirAcharya
Tags:ad-rotator DarkSword iOS js Loader supply-chain web-drive-by


Avatar
KabirAcharya
Live poisoned tldjs 2.3.1 body with a 2,571-byte mobile appendage. It loads both the confirmed DarkSword chain and a separate traffic-rotation branch; no single family signature is assigned.

Intelligence


File Origin
# of uploads :
1
# of downloads :
104
Origin country :
AU AU
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
evasive repaired
Verdict:
inconclusive
YARA:
1 match(es)
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2026-09-05 11:36:42 UTC
File Type:
Text (JavaScript)
AV detection:
3 of 24 (12.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Command and Scripting Interpreter: JavaScript
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Distributed via drive-by

Comments