MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 69764623ad18cac42c17d13d243c31f73ea24727b72374c4e7d5f93b6e46bccc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DonutLoader


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 69764623ad18cac42c17d13d243c31f73ea24727b72374c4e7d5f93b6e46bccc
SHA3-384 hash: 29021fb5567351293f970097edfa7ab4ebc3ec829ef50fe0c7cfefbf3b848adffaa6e5cc72e97ca12b594851d949e303
SHA1 hash: c471a56195adaba864af4e574fa4c664ef5d26d5
MD5 hash: 80096ba42466ca91e102f1c15d6015be
humanhash: september-arkansas-table-oscar
File name:New order N 2160848.js
Download: download sample
Signature DonutLoader
File size:6'727'950 bytes
First seen:2026-03-18 12:44:43 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 98304:al3KA97+dLV27WVdJAmAlTfs9hGX13qqqAjnUMLNCMgeKIQ/GKVBc36GpBslZfft:acA9Klk8dKBlTXzpxB1KIQrVC36JRZ1
TLSH T13666B604E31C5A70FAAD562CD57E7E60890863476244EF3D36BC471DB3A272B139C9EA
Magika javascript
Reporter James_inthe_box
Tags:donutloader exe js

Intelligence


File Origin
# of uploads :
1
# of downloads :
136
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
70%
Tags:
autoit emotet
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug autoit dropper evasive expired-cert fingerprint keylogger masquerade obfuscated repaired
Verdict:
Malicious
File Type:
js
Detections:
HEUR:Trojan-Dropper.Script.Generic HEUR:Trojan.Script.Generic HEUR:Trojan.Script.SAgent.gen
Gathering data
Result
Malware family:
donutloader
Score:
  10/10
Tags:
family:donutloader discovery execution loader
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Checks computer location settings
Executes dropped EXE
Detects DonutLoader
DonutLoader
Donutloader family
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments