MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a4daa30a2ef6943d8eec7759246f6584bfd679b094cb8b66302355500a036b9a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Kimsuky


Vendor detections: 4


Intelligence 4 IOCs YARA 1 File information Comments

SHA256 hash: a4daa30a2ef6943d8eec7759246f6584bfd679b094cb8b66302355500a036b9a
SHA3-384 hash: 6a97f357c7c574762b3159d4629b2a604d40751aa2ec2d9dbe45b6b416b801d74d504c98a705416bf393d7620a7e7220
SHA1 hash: 15d9903e7d475d6927e0687ca238642678c90d2f
MD5 hash: 582a033da897c967faade386ac30f604
humanhash: oranges-undress-batman-video
File name:bg.js
Download: download sample
Signature Kimsuky
File size:3'784 bytes
First seen:2022-08-09 15:12:17 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 96:aD7k2DyfQ+/NuGwByZ6Xps7naMvzgxX3J1X6Ue:eItNu5BysXpQmfX6Ue
TLSH T1D8718688F7CA9DC956B131761A8F01CC2CAF5422280CDC56B54CF8E14B949B541BEFB0
Reporter sysopfb1
Tags:js Kimsuky SharpExt


Avatar
sysopfb
SharpExt extension javascript

Intelligence


File Origin
# of uploads :
1
# of downloads :
397
Origin country :
n/a
Vendor Threat Intelligence
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Malicious sample detected (through community Yara rule)
Behaviour
Behavior Graph:
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:APT_SharpTongue_JS_SharpExt_Chrome_Extension
Author:threatintel@volexity.com
Description:A malicious Chrome browser extention used by the SharpTongue threat actor to steal mail data from a victim
Reference:https://www.volexity.com/blog/2022/07/28/sharptongue-deploys-clever-mail-stealing-browser-extension-sharpext/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments