🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 850e9a04d7b41ea503c82351f9a0bb729cbc2dd8e361da6ca9c90b4f39d8405c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Hades


Vendor detections: 2


Intelligence 2 IOCs YARA 1 File information Comments

SHA256 hash: 850e9a04d7b41ea503c82351f9a0bb729cbc2dd8e361da6ca9c90b4f39d8405c
SHA3-384 hash: 874ea558de2a13097d845f234894dded834524bf9fb5beda152be81e497bf191eb57372248943cde58f2a526cf2bc325
SHA1 hash: 948d4705f9f94ce1eb95821a1bb7b890bb7f2c13
MD5 hash: af300dbb50812ee4f119ac8170e9fe8d
humanhash: sodium-cold-triple-tango
File name:hades_discord_injection.js
Download: download sample
Signature Hades
File size:5'602 bytes
First seen:2026-09-12 06:39:21 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 96:5u+wFNQZuHsZGmKGzW4bM9GZwWAvb7cQ/ZQdVVeCMhb:5u+wFNQDZVq4bMnWAvb7WdVVeCMhb
TLSH T164C18449B01611588572633A9D67C125F336B037248946523F3CC2593FB7A69B263FDD
Magika javascript
Reporter devmihaylov
Tags:discord electron extracted Hades Injection js stealer


Avatar
devmihaylov
Hades, a licensed crimeware kit sold as a streaming application, combining browser and wallet theft, live Discord credential interception, a socket.io remote access channel and a desktop lockdown. Recovered Discord injection, EXTRACTED from the bytecode rather than dropped to disk. Installs a session.webRequest hook reading Discord API request bodies before encryption, capturing plaintext passwords at login and at change, the TOTP seed at 2FA enrolment, backup codes, and tokens from local storage and the Authorization header. Also hooks BrowserWindow.prototype.loadURL to disable QR login, hiding the button with insertCSS and deleting the qrCodeContainer svg with a MutationObserver, so the password form becomes the only way in.

Intelligence


File Origin
# of uploads :
1
# of downloads :
147
Origin country :
BG BG
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
repaired
Verdict:
inconclusive
YARA:
1 match(es)
Tags:
SVG
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:dsc
Author:Aaron DeVera
Description:Discord domains

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Dropped by
Hades
  
Delivery method
Other

Comments