MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b15da71145d6239a23eb1ea7d885ca7f146e355a293c0db8f7ca31167392f9ae. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: b15da71145d6239a23eb1ea7d885ca7f146e355a293c0db8f7ca31167392f9ae
SHA3-384 hash: ec3b85a3521dc7d4446542169ef129b9a93c89abab5c0eab99f41f5ed1911ed3cf65d0b4fdd97a7a208ad520acce8460
SHA1 hash: 8290fbe67ae6948dcdad58f7d6d95489dfe548f9
MD5 hash: c2f53e4d1f2bb0473227702eb535f97e
humanhash: kentucky-network-quebec-paris
File name:PO-003727_Updated_Order_Sheet_20260408.js
Download: download sample
File size:358'824 bytes
First seen:2026-05-19 12:29:06 UTC
Last seen:2026-05-20 16:49:45 UTC
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 6144:kzZvMz3rSGdiE4gqqXRxkxYvm+nDoSJ2hf/CM/lXWe3r2yeD+e2D6dyY:sZ0zeDuR60m+nDoXtAe36J2D6B
TLSH T1477415ACDDDC0638E6B7D65CDC988A4368936DABAA0CF90501C037DA1737547BD81A2F
TrID 66.6% (.TXT) Text - UTF-16 (LE) encoded (2000/1)
33.3% (.MP3) MP3 audio (1000/1)
Magika txt
Reporter JAMESWT_WT
Tags:js solar-sanat-net

Intelligence


File Origin
# of uploads :
2
# of downloads :
136
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
90.9%
Tags:
stration virus shell
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
aes base64 conhost crypto encrypted evasive masquerade obfuscated overlay packed powershell repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-04-08T02:43:00Z UTC
Last seen:
2026-05-21T10:02:00Z UTC
Hits:
~1000
Gathering data
Threat name:
Script-WScript.Trojan.Heuristic
Status:
Malicious
First seen:
2026-04-08 09:32:43 UTC
File Type:
Text (JavaScript)
AV detection:
10 of 36 (27.78%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
collection discovery execution
Behaviour
Enumerates system info in registry
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
Browser Information Discovery
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
System Time Discovery
Drops file in Windows directory
Accesses Microsoft Outlook profiles
Command and Scripting Interpreter: PowerShell
Checks computer location settings
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments