🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9f1125bf7dd9ea6545df89f856157fefe2275efb2bd900492e14e3df02264dfa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LxBaseRAT


Vendor detections: 10


Intelligence 10 IOCs YARA 1 File information Comments

SHA256 hash: 9f1125bf7dd9ea6545df89f856157fefe2275efb2bd900492e14e3df02264dfa
SHA3-384 hash: 27c7186b20c5924492642edeea3f65e6094e962c14f9017bc566b3ee254dd323186f7587a227672abd22ffbf8f11e8f2
SHA1 hash: c877b75ffbbf9a15b7dcb5080c80ae28cf9b1199
MD5 hash: ea26758135d1ad4c8764b07165e347a4
humanhash: enemy-east-tennessee-muppet
File name:BÁO GIÁ P1456 1331 0.js
Download: download sample
Signature LxBaseRAT
File size:714'089 bytes
First seen:2026-10-05 08:57:40 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 12288:XBwVJteFaCjTt1g1rP79i3IoPeR6PGpJbhweKV1ELUfqEyfpKnZPC1Z/eXDVsoAB:RwVJtCaCjXg979EIKmvbbyeKVqLXEyBd
TLSH T19CE49E31627C905D2D67A46B637BB123761EFB2DD10A3B4005FE43C271E61BA923789B
Magika javascript
Reporter abuse_ch
Tags:js LxBaseRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
167
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
encrypted evasive obfuscated repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-10-05T01:03:00Z UTC
Last seen:
2026-10-07T06:37:00Z UTC
Hits:
~100
Result
Threat name:
Clipboard Hijacker, Discord Token Steale
Detection:
malicious
Classification:
evad.troj.spyw
Score:
100 / 100
Signature
.NET source code contains process injector
.NET source code references suspicious native API functions
Allocates memory in foreign processes
Antivirus detection for dropped file
Benign windows process drops PE files
C2 URLs / IPs found in malware configuration
Contains functionality to register a low level keyboard hook
Creates a thread in another existing process (thread injection)
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Injects a PE file into a foreign processes
Installs a global keyboard hook
JScript performs obfuscated calls to suspicious functions
Multi AV Scanner detection for submitted file
Sample uses string decryption to hide its real strings
Sigma detected: Scheduled temp file as task from temp location
Sigma detected: Silenttrinity Stager Msbuild Activity
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Tries to detect sleep reduction / modifications
Tries to harvest and steal browser information (history, passwords, etc)
Uses schtasks.exe or at.exe to add and modify task schedules
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
WScript reads language and country specific registry keys (likely country aware script)
Yara detected Clipboard Hijacker
Yara detected Discord Token Stealer
Yara detected LxBase RAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1982238 Sample: B#U00c1O GI#U00c1 P1456 1331 0.js Startdate: 05/10/2026 Architecture: WINDOWS Score: 100 71 mr-b01.tm-azurefd.net 2->71 73 ip-api.com 2->73 75 casoneroutegold-prod-bggfgca0dkaag8a8.b01.azurefd.net 2->75 95 Suricata IDS alerts for network traffic 2->95 97 Found malware configuration 2->97 99 Sigma detected: Scheduled temp file as task from temp location 2->99 101 10 other signatures 2->101 10 wscript.exe 1 4 2->10         started        14 updateagenteod.exe 2->14         started        signatures3 process4 file5 67 C:\Users\user\AppData\...\updateagenteod.exe, PE32 10->67 dropped 69 C:\Users\user\AppData\...\cacheeod.store, data 10->69 dropped 111 Benign windows process drops PE files 10->111 113 JScript performs obfuscated calls to suspicious functions 10->113 115 Windows Scripting host queries suspicious COM object (likely to drop second stage) 10->115 117 WScript reads language and country specific registry keys (likely country aware script) 10->117 16 updateagenteod.exe 4 10->16         started        20 updateagenteod.exe 10->20         started        119 Antivirus detection for dropped file 14->119 signatures6 process7 file8 55 C:\Users\user\AppData\...\updateagenteod.exe, PE32 16->55 dropped 57 C:\Users\user\AppData\Local\Temp\lxA2E6.tmp, XML 16->57 dropped 81 Found many strings related to Crypto-Wallets (likely being stolen) 16->81 83 Writes to foreign memory regions 16->83 85 Allocates memory in foreign processes 16->85 87 Injects a PE file into a foreign processes 16->87 22 MSBuild.exe 15 68 16->22         started        27 schtasks.exe 1 16->27         started        89 Antivirus detection for dropped file 20->89 91 Uses schtasks.exe or at.exe to add and modify task schedules 20->91 93 Tries to detect sleep reduction / modifications 20->93 signatures9 process10 dnsIp11 77 64.89.160.127, 4561, 49711 GHOSTYNETWORKSUS Luxembourg 22->77 79 ip-api.com 208.95.112.1, 49712, 80 TUT-AS-TotalUptimeTechnologiesLLCUS United States 22->79 65 C:\Users\user\AppData\Local\...\msasn1.dll, PE32+ 22->65 dropped 103 Found many strings related to Crypto-Wallets (likely being stolen) 22->103 105 Contains functionality to register a low level keyboard hook 22->105 107 Tries to harvest and steal browser information (history, passwords, etc) 22->107 109 Installs a global keyboard hook 22->109 29 .dfc_f63462ce.dat 2 22->29         started        32 .dfc_fd614ad8.dat 22->32         started        34 .dfc_53e64776.dat 22->34         started        38 11 other processes 22->38 36 conhost.exe 27->36         started        file12 signatures13 process14 file15 121 Writes to foreign memory regions 29->121 123 Allocates memory in foreign processes 29->123 125 Creates a thread in another existing process (thread injection) 29->125 41 conhost.exe 29->41         started        127 Tries to harvest and steal browser information (history, passwords, etc) 32->127 43 conhost.exe 32->43         started        45 conhost.exe 34->45         started        59 C:\Users\user\AppData\...\.dfc_fd614ad8.dat, PE32+ 38->59 dropped 61 C:\Users\user\AppData\...\.dfc_f63462ce.dat, PE32+ 38->61 dropped 63 C:\Users\user\AppData\...\.dfc_53e64776.dat, PE32+ 38->63 dropped 129 Installs a global keyboard hook 38->129 47 conhost.exe 38->47         started        49 conhost.exe 38->49         started        51 cvtres.exe 1 38->51         started        53 4 other processes 38->53 signatures16 process17
Verdict:
inconclusive
YARA:
1 match(es)
Threat name:
Script.Trojan.Multiverze
Status:
Malicious
First seen:
2026-10-05 08:58:38 UTC
File Type:
Text (JavaScript)
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
unc_dotnet_stealer_002
Result
Malware family:
n/a
Score:
  7/10
Tags:
collection discovery execution persistence spyware stealer
Behaviour
Scheduled Task/Job: Scheduled Task
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
outlook_office_path
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Reads the TCP/IP host and domain name from the registry
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Looks up external IP address via web service
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments