🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e950d03c58d49e28e31df8afeefca1f3b3d2cd6b697c40adfee1a4f6fe18f004. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 2 File information Comments

SHA256 hash: e950d03c58d49e28e31df8afeefca1f3b3d2cd6b697c40adfee1a4f6fe18f004
SHA3-384 hash: 30fd159e76eed5d3793a8ca2cdaa6f5d80948e5ff33da244a003656551d13ea5ace143c36424f97f42857a5cfd725f51
SHA1 hash: 1a1c3350fc64b0b77623683bc6757b8fecb3d6a5
MD5 hash: c0bb1be1997085f666f4cf0509648859
humanhash: kansas-utah-enemy-hotel
File name:dist.zip
Download: download sample
File size:25'935 bytes
First seen:2026-09-09 10:37:11 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:QOJrUiXyNY7hQ9WiZvbCgjWfRyw5O5gpsSKAeguuOi:QOJnv7e59CSMYwkKzeVi
TLSH T1A9C2E19285DB857AC75BF7B403030092353DAB2E66E53BE48A0C7F268E949DA437553C
Magika zip
Reporter Anonymous
Tags:BlueMoonEK TA412 zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
36
Origin country :
US US
File Archive Information

This file archive contains 6 file(s), sorted by their relevance:

File name:icon64.png
File size:3'523 bytes
SHA256 hash: 908a31c5b0080fd361cdb0c1c8afee7bf2010ff4176eff9ff66cd3cdcb8712c1
MD5 hash: 3deefe746e55dbdb1ac8cc76611e729c
MIME type:image/png
File name:icon32.png
File size:1'397 bytes
SHA256 hash: 980a0e324bdfb69a5f2bb0f13f7e890265de696bef84b629cba1000d60208a21
MD5 hash: a1f1495d92b00dd1696c18d623992cee
MIME type:image/png
File name:icon16.png
File size:630 bytes
SHA256 hash: 37e85ab8b1c5aa8ae935958411e51abb7aa96ace31e9360b31ca7c1438aa7a82
MD5 hash: 4c0deba394e095ee5edd45f4de4d3ac5
MIME type:image/png
File name:manifest.json
File size:1'022 bytes
SHA256 hash: 729c93ed079b1cbf6d8daf19972213b6613f90679b6c3084c97e0e0715198d17
MD5 hash: 729c1d7b00c508310ade77472f67145a
MIME type:application/json
File name:icon128.png
File size:8'895 bytes
SHA256 hash: 7f81778cfa877d25054dc75f65fc5098dfa009c8cb7a4cde9d5d7c823771e64c
MD5 hash: ccc5d07fcb2b0e016f08dd3a27594778
MIME type:image/png
File name:background.js
File size:35'972 bytes
SHA256 hash: 353b5bd2780c1b0c07c1283d83cf16cf1e9ec226c17b2d09d56848893f9d98ee
MD5 hash: 775350a89885268a4ddbc1693620f62c
MIME type:text/plain
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
JS File - Malicious
Payload URLs
URL
File name
https://extension-management-portal.kmjukilo-lkjh.workers.dev
JS File
Verdict:
inconclusive
YARA:
2 match(es)
Tags:
Zip Archive
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Command and Scripting Interpreter: JavaScript
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_obfuscated_JS_obfuscatorio
Author:@imp0rtp3
Description:Detect JS obfuscation done by the js obfuscator (often malicious)
Reference:https://obfuscator.io

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments