MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6cc9f3bfc2e987c6a140177497f6ef916c91c72e391932087f1245929f3ce11f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SocGholish


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 6cc9f3bfc2e987c6a140177497f6ef916c91c72e391932087f1245929f3ce11f
SHA3-384 hash: 3c4d4e3b93f329e0c288b9cab6e6d51b2d6b39795ff5d2c63d66f26bd2224b678983c6865820d6f76e95ba33eb5123c8
SHA1 hash: dff412e124515b5ece0cf29f1965b296351c353c
MD5 hash: b218ec45904bfbb4ab83c6ca2b4f029d
humanhash: march-nitrogen-autumn-uniform
File name:Chrome.Update.518fbd.js
Download: download sample
Signature SocGholish
File size:1'785 bytes
First seen:2022-02-17 07:18:02 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 48:1omh8hluRWOWpR0JWng7SlW1Ii7swsGDT8gx:LklucSYggaIi7/d8O
TLSH T19C31FF8C33CFA04C47DB37089B3E450DE8FDDE23E568857CA9064684A5E482A47996FD
Reporter ankit_anubhav
Tags:js socgholish

Intelligence


File Origin
# of uploads :
1
# of downloads :
493
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
obfuscated
Result
Verdict:
MALICIOUS
Threat name:
Script.Downloader.SLoad
Status:
Malicious
First seen:
2022-02-17 07:18:12 UTC
File Type:
Text (JavaScript)
AV detection:
6 of 27 (22.22%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Modifies system certificate store
Suspicious use of AdjustPrivilegeToken
Drops file in Windows directory
Blocklisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments