MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 73a36bb36ea6e4c879a47474e065e8f2dddcdac1a01ed3a340cb5ea5b6ea4e34. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA 1 File information Comments

SHA256 hash: 73a36bb36ea6e4c879a47474e065e8f2dddcdac1a01ed3a340cb5ea5b6ea4e34
SHA3-384 hash: 5d35dc1329f5cb6c238dce4f0a540f671ac279ab1c7e2d049dd4df4aad273c6a66812d8367eb69d9d23ea69c9844cc3c
SHA1 hash: abb07f83219e7f0c1ab7bb9eefb204a90f541c6a
MD5 hash: f8d9dd10001778e982bb93e0e227383c
humanhash: vermont-fanta-steak-green
File name:script1-from-2nd-obf-script.bin
Download: download sample
File size:10'610 bytes
First seen:2026-06-26 10:34:46 UTC
Last seen:2026-06-26 11:00:39 UTC
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 192:a9WlsKFZc0JOMbHea2wVdrfz/PlKnu+o/ZxpSOGVwWR3W:a9mby4taCauWR3W
TLSH T117222F4C3DED71AD427EB374633A8420E9067913D091D3A474AFD0B8AF7AA21F671D64
Magika javascript
Reporter marsomx
Tags:Crafted8088 js

Intelligence


File Origin
# of uploads :
3
# of downloads :
10
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
masquerade repaired
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Command and Scripting Interpreter: JavaScript
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments