MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 884f1552fe526d72f01035f8fd1b565d254b52fbbfcb6cb034f34598794f7d7d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SmartLoader


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 884f1552fe526d72f01035f8fd1b565d254b52fbbfcb6cb034f34598794f7d7d
SHA3-384 hash: a57ff292d971b1fdf1470cf88a16ba253ebaf991c79b8e59f2c2ea629850c3d947fd64fb4e4b48829f3282fc11aa82ca
SHA1 hash: a5064f36a48ef1914c62879098bf9d49a58314c5
MD5 hash: 00ba06448d5e03dfbfa60a4bc2219193
humanhash: diet-saturn-kansas-connecticut
File name:asset.txt
Download: download sample
Signature SmartLoader
File size:306'113 bytes
First seen:2024-11-17 10:50:46 UTC
Last seen:2025-03-24 10:55:18 UTC
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 3072:kdh3S5Bw/cCnmToOU4A9MK1WJub4++YsoC4kQJ7jqejB2mzvuKwaSBR/CEuI3wX:kDCfw/cepjPu7Jub4LYsoLqFdKw3/gX
TLSH T14F5482B6A04C04F059EF86A6DC6BBDAB91BAD5F94306664B0F2CF1A73520172C7D9C07
Magika javascript
Reporter aachum
Tags:js SmartLoader


Avatar
iamaachum
https://github.com/user-attachments/files/17562972/Program.zip

Must be loaded through a LuaJIT executable for the script to work.

SmartLoader C2: http://89.169.13.169/api/OWUsODEsN2QsYTAsYTMsOGEsOGMsOTUsNmIsODIs

Intelligence


File Origin
# of uploads :
2
# of downloads :
85
Origin country :
ES ES
Vendor Threat Intelligence
Verdict:
Suspicious
Score:
50%
Tags:
virus micro gates
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
masquerade
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
52 / 100
Signature
Sigma detected: Cscript/Wscript Uncommon Script Extension Execution
Sigma detected: WScript or CScript Dropper
Uses an obfuscated file name to hide its real file extension (double extension)
Behaviour
Behavior Graph:
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2024-10-25 03:59:05 UTC
File Type:
Text (Lua)
AV detection:
3 of 38 (7.89%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

SmartLoader

Java Script (JS) js 884f1552fe526d72f01035f8fd1b565d254b52fbbfcb6cb034f34598794f7d7d

(this sample)

  
Delivery method
Distributed via web download

Comments