MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 80c920896f1aac2f0291726ad3569fc999ddc4beadd3c41c11d4303fa012791d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 7
| SHA256 hash: | 80c920896f1aac2f0291726ad3569fc999ddc4beadd3c41c11d4303fa012791d |
|---|---|
| SHA3-384 hash: | 49ce7e17e5abcd044834e9e4f5f431a10394351e851fc3e0ee7422b5e5ae87f60ee76e4ac7f17bf7ad3f57cdf225c2c5 |
| SHA1 hash: | e80f40b435caeb7c2e79675fc9f4e475e5409c26 |
| MD5 hash: | 00f0825f890d85c8d2f421f7c040e96b |
| humanhash: | black-hamper-neptune-burger |
| File name: | fuck_niggers_0.hta |
| Download: | download sample |
| File size: | 496 bytes |
| First seen: | 2025-05-18 10:33:33 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | text/html |
| ssdeep | 12:kxvsCk9cE3MobZ/XU9eJyqqrlFQICHtknp9xYI:kbxs/k99qq5FlQI |
| TLSH | T117F0D4E71CABC90FF2E154024F95619824C5019F74C4981C50F9BFB9B97975EDE16170 |
| Magika | txt |
| Reporter | |
| Tags: | hta |
Intelligence
File Origin
# of uploads :
1
# of downloads :
74
Origin country :
DEVendor Threat Intelligence
Detection(s):
Verdict:
Clean
Score:
89.3%
Tags:
n/a
Result
Verdict:
Malicious
File Type:
HTA File - Malicious
Payload URLs
URL
File name
https://daftar.site/4PCF/fuck_niggers_0.hta?ch=1&js=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJKb2tlbiIsImV4cCI6MTc0NzU3MTM3OCwiaWF0IjoxNzQ3NTY0MTc4LCJpc3MiOiJKb2tlbiIsImpzIjoxLCJqdGkiOiIzMTA5Z240YjI5N25qb3NwYm8wOXIxazUiLCJuYmYiOjE3NDc1NjQxNzgsInRzIjoxNzQ3NTY0MTc4NjU3MzY5fQ.rcdyhRoVl2HQSK-2KJ1tnj8zAlCk6tTKOqdh1YKhLtQ&sid=006a431e-33d3-11f0-a7b0-416bed37c69d');
HTA File
Verdict:
Malicious
Threat level:
10/10
Confidence:
100%
Tags:
base64 evasive fingerprint obfuscated
Verdict:
Malicious
Labled as:
JS/Redirector.QNO trojan
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Antivirus detection for URL or domain
Behaviour
Behavior Graph:
Score:
1%
Verdict:
Benign
File Type:
SCRIPT
Threat name:
Script-JS.Trojan.Redirector
Status:
Malicious
First seen:
2025-05-18 10:34:18 UTC
File Type:
Text (HTML)
Extracted files:
1
AV detection:
7 of 37 (18.92%)
Threat level:
5/5
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
6/10
Tags:
defense_evasion discovery trojan
Behaviour
Modifies Internet Explorer settings
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Checks whether UAC is enabled
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
hta 80c920896f1aac2f0291726ad3569fc999ddc4beadd3c41c11d4303fa012791d
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.