🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e1c18c4e147bfacfe050d441bde8ac4591f2e7d4320dbc28da78b61647fbb04d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: e1c18c4e147bfacfe050d441bde8ac4591f2e7d4320dbc28da78b61647fbb04d
SHA3-384 hash: eb8838db6f339375f738a1d3b628c44ec935f1de6b13187fb685614368c9146e17558b3f63b604fd25d89d85a07624d8
SHA1 hash: 0a0bb1334dd4aa5a119ab50d89def9e2b2443ff2
MD5 hash: 907b2b1136f064e7beba0aed1ff1a383
humanhash: red-network-xray-fifteen
File name:JAG93498680733_20260911_044325_690d130890.js
Download: download sample
File size:1'305'860 bytes
First seen:2026-09-11 04:48:56 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 24576:Ctssf3ue5hIIbTq6FdEEDtssf3ue5hIIbTq6FdEEktssf3ue5hIIbTq6FdEEDtsz:Ctssf3ue5hIIbTq6FdEEDtssf3ue5hIy
TLSH T146553024327F930870F352DC95EC1A5246BEF36A263F67AC82B52D8C23E2D425D95B53
TrID 66.6% (.TXT) Text - UTF-16 (LE) encoded (2000/1)
33.3% (.MP3) MP3 audio (1000/1)
Magika txt
Reporter KodaDr
Tags:js Loader upcrypter

Intelligence


File Origin
# of uploads :
1
# of downloads :
119
Origin country :
LV LV
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm base64 downloader encrypted fingerprint ipconfig lolbin netsh powershell powershell repaired
Gathering data
Result
Malware family:
n/a
Score:
  7/10
Tags:
execution persistence privilege_escalation
Behaviour
Gathers network information
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Event Triggered Execution: Netsh Helper DLL
Command and Scripting Interpreter: PowerShell
Checks computer location settings
Deletes itself
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments