🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dd9ddca86037fe3da0536b80fc98a72d73618d14a99bcb73c1c13bd401f68593. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Kimsuky


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: dd9ddca86037fe3da0536b80fc98a72d73618d14a99bcb73c1c13bd401f68593
SHA3-384 hash: 88df40620712908b5a7384358d7546d30f0ea732ed6ec523e4ac9669301e224336a1dc14d3479e17bb32012ef603fe2d
SHA1 hash: 75d495f76e4b0fc8ee3d4c5d646afd96fd818143
MD5 hash: 2af6fb5bc3137eb297c6560e267d8193
humanhash: nuts-winner-alabama-autumn
File name:dd9ddca86037fe3da0536b80fc98a72d73618d14a99bcb73c1c13bd401f68593
Download: download sample
Signature Kimsuky
File size:1'529 bytes
First seen:2025-02-09 09:06:30 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 24:256KNA1h6RYutRDRBHObRDRBJ9J6v3ARjD9hsfRbIRIiMmav7jiuaWHk/AGYq8Fx:q6yQh6dtXBubXBXgvO54RbBTTjuWHEAD
TLSH T19A31471913E93624AB8C08B18CEF9C85DE676E96151DC400D887C6807D58E7CC4FAEA8
Magika javascript
Reporter TheRavenFile
Tags:APT43 forceCopy js Kimsuky


Avatar
RakeshKrish12
Source: https://github.com/TheRavenFile/Daily-Hunt/blob/main/KIMSUKY-APT43%20%F0%9F%87%B0%F0%9F%87%B5

Intelligence


File Origin
# of uploads :
1
# of downloads :
151
Origin country :
IN IN
Vendor Threat Intelligence
Verdict:
Malicious
Score:
90.9%
Tags:
virus shell spawn
Result
Threat name:
n/a
Detection:
malicious
Classification:
expl.evad
Score:
80 / 100
Signature
Bypasses PowerShell execution policy
JScript performs obfuscated calls to suspicious functions
Multi AV Scanner detection for submitted file
Sigma detected: Suspicious PowerShell Parameter Substring
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript starts Powershell (via cmd or directly)
Behaviour
Behavior Graph:
Threat name:
Script-JS.Trojan.Heuristic
Status:
Malicious
First seen:
2025-02-07 04:22:38 UTC
File Type:
Text (JavaScript)
AV detection:
10 of 38 (26.32%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Command and Scripting Interpreter: PowerShell
Enumerates physical storage devices
System Location Discovery: System Language Discovery
System Network Configuration Discovery: Internet Connection Discovery
Checks computer location settings
Downloads MZ/PE file
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments