🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a9bea5f89984d47dd60216b0a0b064e8c7e8057e0c10509faa4a2d8d641eb73b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PivotC2


Vendor detections: 4


Intelligence 4 IOCs YARA 1 File information Comments

SHA256 hash: a9bea5f89984d47dd60216b0a0b064e8c7e8057e0c10509faa4a2d8d641eb73b
SHA3-384 hash: b123bd97e49d5fc5fa776265a66d9061390dffee29d4ffa25f4c8ae929067fe67d456b3b94d07bd1d85c0071b285334b
SHA1 hash: 86887dc1952c24617c28ac30d55b6ac0f0c950df
MD5 hash: fd9970758e5a84d096ff0b978429b982
humanhash: zebra-video-may-queen
File name:live_146.103.99.177_9443_decoded.js
Download: download sample
Signature PivotC2
File size:35'686 bytes
First seen:2026-09-11 10:39:03 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 384:NhC4inUX7S6a3L5fxjYhanLcXLqMk/AJf3ft:NhC4inUXutZxU6ANft
TLSH T10EF2848ADDE620246533F2794B9F9005F27AE1070109CE54BE4CD2E0AF64BB855EDFE9
Magika javascript
Reporter SOCRadarSTRU
Tags:js PivotC2 STRU

Intelligence


File Origin
# of uploads :
1
# of downloads :
36
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
expand lolbin repaired
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Command and Scripting Interpreter: JavaScript
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:testlumma

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments