MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 8f1a14fb20df465ce4946cf546dfd4ced1eba5b160c6f36e6bd7177901bc82a9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 9
| SHA256 hash: | 8f1a14fb20df465ce4946cf546dfd4ced1eba5b160c6f36e6bd7177901bc82a9 |
|---|---|
| SHA3-384 hash: | cc23096b8f1233ad67108e190ff7dfdc5888b9db6ea1638e7205978f6383fa1bfff084a26ee107d20d566158a7c841f1 |
| SHA1 hash: | 9f2b9e0dc6a6f130389e9b0560884225175db8d8 |
| MD5 hash: | a0c51c8fb649e848ede220292d05b89f |
| humanhash: | november-jig-beryllium-fillet |
| File name: | JSload.hta |
| Download: | download sample |
| File size: | 14'952 bytes |
| First seen: | 2026-08-13 14:12:45 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | text/html |
| ssdeep | 48:3/o52Jio5xEJYYPa95uuuugBJ+kQO4tKPpuuuuuuHto5Ro5fSIbJ/o5UG:PoQJiofEJRy96BR4ao7oFSMJ/op |
| TLSH | T1D36251BAAB38F5E0C2C7D4FC140E7CC6140CCA0BD124AE7E785D4537931862D8A2A06F |
| Magika | html |
| Reporter | |
| Tags: | hta |
Intelligence
File Origin
# of uploads :
1
# of downloads :
42
Origin country :
DEVendor Threat Intelligence
No detections
Result
Verdict:
Malicious
File Type:
HTA File - Malicious
Payload URLs
URL
File name
http://209.54.103.153/40/goodthingsforbestfeelingsformebest.jS
HTA File
Behaviour
BlacklistAPI detected
Verdict:
Malicious
Threat level:
10/10
Confidence:
100%
Tags:
powershell
Verdict:
Malicious
Labled as:
VBS.Asthma.2.6E77F4FF
Verdict:
Malicious
File Type:
html
First seen:
2026-08-13T13:00:00Z UTC
Last seen:
2026-08-14T01:49:00Z UTC
Hits:
~10
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
80 / 100
Signature
Antivirus / Scanner detection for submitted sample
Encrypted powershell cmdline option found
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for submitted file
PowerShell case anomaly found
Sigma detected: Suspicious Encoded PowerShell Command Line
Sigma detected: Suspicious MSHTA Child Process
Sigma detected: Suspicious PowerShell Parameter Substring
Behaviour
Behavior Graph:
Score:
100%
Verdict:
Malware
File Type:
SCRIPT
Gathering data
Threat name:
Script-WScript.Trojan.Asthma
Status:
Malicious
First seen:
2026-08-13 14:13:35 UTC
File Type:
Text (HTML)
Extracted files:
1
AV detection:
10 of 23 (43.48%)
Threat level:
5/5
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
8/10
Tags:
discovery execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Executes a command shell one-liner
System Location Discovery: System Language Discovery
Checks computer location settings
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
hta 8f1a14fb20df465ce4946cf546dfd4ced1eba5b160c6f36e6bd7177901bc82a9
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.