MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 771a69e7b0b79becc72c13b98806e9ce6262768aa7af5083633c099ec2fadc94. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 8
| SHA256 hash: | 771a69e7b0b79becc72c13b98806e9ce6262768aa7af5083633c099ec2fadc94 |
|---|---|
| SHA3-384 hash: | c3f3af7f69285153aec6e22580971fe8bed09e00b8254d9720913ad3e307f4b6b4c5408ec762181c8be22390621df4d8 |
| SHA1 hash: | 2525d7d56f55ca521a58eae5173f5aacab9f4e87 |
| MD5 hash: | bd40bd19c724a331eace0d852671e01a |
| humanhash: | moon-uranus-coffee-red |
| File name: | fuck_niggers_49.hta |
| Download: | download sample |
| File size: | 497 bytes |
| First seen: | 2025-05-18 23:53:19 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | text/html |
| ssdeep | 12:kxvsCk9cE3Mod/XUKTqJLmYEtCX1zPiBYI:kbxu/kKT5PU1zPiOI |
| TLSH | T13EF00EBF084BC90DA6E029898A949600E54402611158881A51F85D78F42199E8D05436 |
| Magika | txt |
| Reporter | |
| Tags: | hta |
Intelligence
File Origin
# of uploads :
1
# of downloads :
118
Origin country :
DEVendor Threat Intelligence
Detection(s):
Verdict:
Malicious
Score:
70%
Tags:
blic sage hype
Result
Verdict:
Malicious
File Type:
HTA File - Malicious
Payload URLs
URL
File name
https://daftar.site/7CCI/fuck_niggers_49.hta?ch=1&js=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJKb2tlbiIsImV4cCI6MTc0NzYxOTM5MiwiaWF0IjoxNzQ3NjEyMTkyLCJpc3MiOiJKb2tlbiIsImpzIjoxLCJqdGkiOiIzMTBjODFzZjZsZjVtajdtMjAwMDNndDAiLCJuYmYiOjE3NDc2MTIxOTIsInRzIjoxNzQ3NjEyMTkyMTY2MTgxfQ.EWUi4GIFnJwtXZoQklZD855M8y_BguKuFzV6Fv_hSpo&sid=cab25316-3442-11f0-bcf2-f1374146b261');
HTA File
Verdict:
Malicious
Threat level:
10/10
Confidence:
100%
Tags:
base64 base64 fingerprint lolbin obfuscated obfuscated tracker
Verdict:
Malicious
Labled as:
JS/Redirector.QNO trojan
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Antivirus detection for URL or domain
Behaviour
Behavior Graph:
Score:
1%
Verdict:
Benign
File Type:
SCRIPT
Threat name:
Script-JS.Trojan.Redirector
Status:
Malicious
First seen:
2025-05-18 23:54:16 UTC
File Type:
Text (HTML)
Extracted files:
1
AV detection:
7 of 24 (29.17%)
Threat level:
5/5
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
6/10
Tags:
defense_evasion discovery trojan
Behaviour
Modifies Internet Explorer settings
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Checks whether UAC is enabled
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
hta 771a69e7b0b79becc72c13b98806e9ce6262768aa7af5083633c099ec2fadc94
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.