🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c258229ec4b1519fb02c5df196b774f131c7d60cf650ff59ca7c97f53d4b9434. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: c258229ec4b1519fb02c5df196b774f131c7d60cf650ff59ca7c97f53d4b9434
SHA3-384 hash: 0039eb85a6b43447e5a9abd58d8a989a66733bbb3936eaac5b5995e207c5572ddff5e1dccb3d720205016218356e8fb5
SHA1 hash: a17e45546d37cc98e0817e893130c23b2d9b7a78
MD5 hash: 6954d7c14eb40c69fda73fc9d6efc046
humanhash: nitrogen-mountain-connecticut-alanine
File name:SI-33488777 BAH eStatement29072026.pdf.js
Download: download sample
File size:4'770'126 bytes
First seen:2026-09-29 12:22:05 UTC
Last seen:2026-09-30 12:01:43 UTC
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 384:pjtec1GKsf0vt+iLWCls3FCmiSNDpSwC4jFSNxnhG/KHwlCILf1xhLfX8tGMzb9b:pjtecg7mV
TLSH T121265EC9FA01F9E1892130079A85710AB7E750C90A52CD0FBFADF6D5FA496E3B015DA3
TrID 66.6% (.TXT) Text - UTF-16 (LE) encoded (2000/1)
33.3% (.MP3) MP3 audio (1000/1)
Magika txt
Reporter James_inthe_box
Tags:exe js

Intelligence


File Origin
# of uploads :
2
# of downloads :
178
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
masquerade repaired
Verdict:
Malicious
File Type:
text
First seen:
2026-09-29T03:40:00Z UTC
Last seen:
2026-10-01T09:32:00Z UTC
Hits:
~100
Gathering data
Threat name:
Script-JS.Downloader.Heuristic
Status:
Malicious
First seen:
2026-09-29 10:26:31 UTC
File Type:
Text (JavaScript)
AV detection:
12 of 38 (31.58%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
discovery execution persistence privilege_escalation
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Reads the TCP/IP host and domain name from the registry
Enumerates connected drives
Creates a file in the Startup directory
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Process spawned unexpected child process
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments