MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 850e9a04d7b41ea503c82351f9a0bb729cbc2dd8e361da6ca9c90b4f39d8405c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Hades
Vendor detections: 2
| SHA256 hash: | 850e9a04d7b41ea503c82351f9a0bb729cbc2dd8e361da6ca9c90b4f39d8405c |
|---|---|
| SHA3-384 hash: | 874ea558de2a13097d845f234894dded834524bf9fb5beda152be81e497bf191eb57372248943cde58f2a526cf2bc325 |
| SHA1 hash: | 948d4705f9f94ce1eb95821a1bb7b890bb7f2c13 |
| MD5 hash: | af300dbb50812ee4f119ac8170e9fe8d |
| humanhash: | sodium-cold-triple-tango |
| File name: | hades_discord_injection.js |
| Download: | download sample |
| Signature | Hades |
| File size: | 5'602 bytes |
| First seen: | 2026-09-12 06:39:21 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | text/plain |
| ssdeep | 96:5u+wFNQZuHsZGmKGzW4bM9GZwWAvb7cQ/ZQdVVeCMhb:5u+wFNQDZVq4bMnWAvb7WdVVeCMhb |
| TLSH | T164C18449B01611588572633A9D67C125F336B037248946523F3CC2593FB7A69B263FDD |
| Magika | javascript |
| Reporter | |
| Tags: | discord electron extracted Hades Injection js stealer |
devmihaylov
Hades, a licensed crimeware kit sold as a streaming application, combining browser and wallet theft, live Discord credential interception, a socket.io remote access channel and a desktop lockdown. Recovered Discord injection, EXTRACTED from the bytecode rather than dropped to disk. Installs a session.webRequest hook reading Discord API request bodies before encryption, capturing plaintext passwords at login and at change, the TOTP seed at 2FA enrolment, backup codes, and tokens from local storage and the Authorization header. Also hooks BrowserWindow.prototype.loadURL to disable QR login, hiding the button with insertCSS and deleting the qrCodeContainer svg with a MutationObserver, so the password form becomes the only way in.Intelligence
File Origin
BGVendor Threat Intelligence
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | dsc |
|---|---|
| Author: | Aaron DeVera |
| Description: | Discord domains |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.