MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 73a914cd8e191f234bece7f1e7ad6e82a00388fa8828d94e1a53c8b60e7591d2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 73a914cd8e191f234bece7f1e7ad6e82a00388fa8828d94e1a53c8b60e7591d2
SHA3-384 hash: 6b9d6b489f3c151e3e6a4ab428b7b691336f8128b4a60db9e65811c933cc55fbdec8fdd832e440d224da397b1520205d
SHA1 hash: 8574d0703be69313549983658ca0110df96f437d
MD5 hash: 7a78946f79afeddcd44f198e6d38ddcb
humanhash: oscar-blossom-undress-avocado
File name:pago.js
Download: download sample
File size:1'115'280 bytes
First seen:2026-08-10 11:55:00 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 192:08pc4BV46t4V4f4B8Ds46t4HHV4itc464V46gqttDtDW43IDg84V464IDtibqgRV:HkxdYqAmP6yi9t/hw
TLSH T17A353466F2DE0302AE7C3465DC1F26E7D67B010DBEC58DA8BDAA8C81965006D2C19D7F
Magika javascript
Reporter James_inthe_box
Tags:exe js

Intelligence


File Origin
# of uploads :
1
# of downloads :
132
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm base64 downloader evasive fingerprint obfuscated overlay powershell repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-08-07T12:42:00Z UTC
Last seen:
2026-08-10T07:54:00Z UTC
Hits:
~1000
Gathering data
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-08-07 22:53:00 UTC
File Type:
Binary
AV detection:
7 of 23 (30.43%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Command and Scripting Interpreter: JavaScript
Command and Scripting Interpreter: PowerShell
Badlisted process makes network request
Process spawned unexpected child process
Malware Config
Dropper Extraction:
https://muddy-sound-e0cd.nodetectonn.workers.dev/OirRw
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments