🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c51e8ea6701918bfb0bb340ddaf7deea21cc6952895399baa63c6ab3fcb573ea. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: c51e8ea6701918bfb0bb340ddaf7deea21cc6952895399baa63c6ab3fcb573ea
SHA3-384 hash: a115ac57378ca4e3371fecb14cd9f13c0822a16272be2974e075045be0b24f8bcee7e2b404ee2f1f6300ded29c9b8cfd
SHA1 hash: b6b761b0d256fa266d15429fd1fae6fb2a8b9b48
MD5 hash: 34fec0bf559927aa44dce7af324cdd86
humanhash: eleven-comet-dakota-moon
File name:OT 1537-7______________________xls.js
Download: download sample
File size:1'678'585 bytes
First seen:2026-10-09 15:01:52 UTC
Last seen:2026-10-09 16:22:19 UTC
File type:Java Script (JS) js
MIME type:application/javascript
ssdeep 24576:DCkJgvrKMYi/U5+G/JhwkCQk419xzIM/AcXe:E
TLSH T1A57543F51EE11D8525B45226C3D0F09D0C637F8469EEDE641038F1B7A2F8680BB999AF
Magika javascript
Reporter abuse_ch
Tags:js

Intelligence


File Origin
# of uploads :
2
# of downloads :
163
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
encrypted masquerade obfuscated repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-10-08T16:20:00Z UTC
Last seen:
2026-10-10T10:57:00Z UTC
Hits:
~1000
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
56 / 100
Signature
Found potential dummy code loops (likely to delay analysis)
Multi AV Scanner detection for submitted file
Sigma detected: WScript or CScript Dropper
Behaviour
Behavior Graph:
Gathering data
Threat name:
Script-JS.Packed.Generic
Status:
Suspicious
First seen:
2026-10-08 19:09:39 UTC
File Type:
Text (JavaScript)
AV detection:
5 of 36 (13.89%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Command and Scripting Interpreter: JavaScript
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments