MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 c493897441710535756b48ee71c1a485df44182fd65bf09455f7fff0d8bbdeba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 4
| SHA256 hash: | c493897441710535756b48ee71c1a485df44182fd65bf09455f7fff0d8bbdeba |
|---|---|
| SHA3-384 hash: | 378c42a28dbcc5b1c7dab626ad196266e58c9f1ae74800945e82ae2ab45197abac0dd014f53dad14c9b212b37acf2066 |
| SHA1 hash: | 5d2b31194eb73a14796a5089af4834974a5f40a9 |
| MD5 hash: | f49a6e3a830b1af275676e8c29a6628f |
| humanhash: | oxygen-cold-finch-oxygen |
| File name: | okbro.hta |
| Download: | download sample |
| File size: | 11'821 bytes |
| First seen: | 2026-07-29 06:34:21 UTC |
| Last seen: | 2026-07-29 08:21:12 UTC |
| File type: | |
| MIME type: | text/html |
| ssdeep | 192:sXHNsGeTHQpD+da6+888+UV7tDoj/pxzi5JYb5QqG5HdXIZd4XthOO:sXX+/DV7k/3i5WaqCXQ4XTOO |
| TLSH | T13732099CFEE162B0F31743DE37AB2C2A122461972008C5C1F94DADE47F467D88663A5B |
| Magika | html |
| Reporter | |
| Tags: | hta |
Intelligence
File Origin
# of uploads :
2
# of downloads :
71
Origin country :
DEVendor Threat Intelligence
No detections
Result
Verdict:
Malicious
File Type:
HTA File - Malicious
Payload URLs
URL
File name
http://excursiionline.ro/a/okbro.hta',u='/z0f76a1d14fd21a8fb5fd0d03e0fdc3d3cedae52f',P='failedChecks',e=Object[a(a0M.c)](a0l)[a(0xd0)](([T,V])=
HTA File
Verdict:
Unknown
Threat level:
2.5/10
Confidence:
100%
Verdict:
Unknown
File Type:
html
Result
Threat name:
n/a
Detection:
clean
Classification:
n/a
Score:
1 / 100
Behaviour
Behavior Graph:
n/a
Score:
18%
Verdict:
Benign
File Type:
SCRIPT
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Html SVG
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-29 07:12:09 UTC
AV detection:
3 of 24 (12.50%)
Threat level:
5/5
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
3/10
Tags:
discovery
Behaviour
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
hta c493897441710535756b48ee71c1a485df44182fd65bf09455f7fff0d8bbdeba
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.