🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 eaece245a205c1275bf2b5a9b9f38238e564834ebc516c19e1fb70fab7b880e6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 5 File information Comments

SHA256 hash: eaece245a205c1275bf2b5a9b9f38238e564834ebc516c19e1fb70fab7b880e6
SHA3-384 hash: 1cc03a0f20791dc4bcd24999e2a3b8fcaf82f839d59d8b6225f900eaad3d53a4257e7018da31a75d9fd3637ba66e00cc
SHA1 hash: f6d08730613a2a8764d6600ac96fa77564c356fe
MD5 hash: 5b5951a42a85c098f4b6f361dda950d8
humanhash: timing-finch-steak-wolfram
File name:HIPAA_Signed_Client#726_JDF11.js
Download: download sample
File size:2'387'308 bytes
First seen:2026-10-01 18:11:20 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 12288:vxltBZQ1uE/GwCg9bGohsufJcQ94vNklOWC6iQ5vhn4amSG6ut+xqHt4wez5c+v2:NYnOcrdIB94NwdxOF3sU/M3l
TLSH T1F7B5898A1708C891D85BEFFF7E31E2E0E1197DC6C7C1299DF754B53CE888525AA88781
Magika javascript
Reporter smica83
Tags:js

Intelligence


File Origin
# of uploads :
1
# of downloads :
184
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
encrypted lolbin msiexec obfuscated repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-10-01T16:42:00Z UTC
Last seen:
2026-10-01T17:33:00Z UTC
Hits:
~10
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
80 / 100
Signature
Injects code into the Windows Explorer (explorer.exe)
JScript performs obfuscated calls to suspicious functions
Sigma detected: Script Initiated Connection to Non-Local Network
Sigma detected: WScript or CScript Dropper
System process connects to network (likely due to code injection or exploit)
Unusual module load detection (module proxying)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
WScript reads language and country specific registry keys (likely country aware script)
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1980899 Sample: HIPAA_Signed_Client#726_JDF11.js Startdate: 01/10/2026 Architecture: WINDOWS Score: 80 55 Sigma detected: WScript or CScript Dropper 2->55 57 Sigma detected: Script Initiated Connection to Non-Local Network 2->57 7 wscript.exe 1 26 2->7         started        12 explorer.exe 2->12         started        14 msiexec.exe 83 43 2->14         started        16 2 other processes 2->16 process3 dnsIp4 47 34.4.104.77, 49716, 80 GOOGLE-GoogleLLCUS United States 7->47 37 C:\Users\user\AppData\Local\...\setupj30.msi, Composite 7->37 dropped 61 System process connects to network (likely due to code injection or exploit) 7->61 63 JScript performs obfuscated calls to suspicious functions 7->63 65 Windows Scripting host queries suspicious COM object (likely to drop second stage) 7->65 67 WScript reads language and country specific registry keys (likely country aware script) 7->67 18 chrome.exe 1 7->18         started        21 msiexec.exe 7->21         started        23 Exodus.exe 8 172 12->23         started        39 C:\Users\user\AppData\Roaming\...\ffmpeg.dll, PE32+ 14->39 dropped 41 C:\Users\user\AppData\Roaming\...xodus.exe, PE32+ 14->41 dropped 69 Injects code into the Windows Explorer (explorer.exe) 14->69 27 explorer.exe 1 14->27         started        file5 signatures6 process7 dnsIp8 45 192.168.2.6, 443, 49713, 49716 unknown unknown 18->45 29 chrome.exe 18->29         started        35 13ac7c3b-cc78-425e...6cde1bb077.tmp.node, PE32+ 23->35 dropped 59 Unusual module load detection (module proxying) 23->59 33 Exodus.exe 1 23->33         started        file9 signatures10 process11 dnsIp12 49 mobile-gtalk.l.google.com 142.251.107.188 GOOGLE-GoogleLLCUS United States 29->49 51 www.google.com 142.251.154.119, 443, 49721, 49728 GOOGLE-GoogleLLCUS United States 29->51 53 4 other IPs or domains 29->53 43 Chrome Cache Entry: 202, PDP-11 29->43 dropped file13
Gathering data
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2026-09-30 01:29:19 UTC
File Type:
Text (JavaScript)
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
credential_access discovery execution persistence stealer
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Browser Information Discovery
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Reads the TCP/IP host and domain name from the registry
System Time Discovery
Drops file in Program Files directory
Drops file in Windows directory
Drops file in System32 directory
Enumerates connected drives
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Unsecured Credentials: Credentials In Files
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:apt_CN_Tetris_JS_advanced_1
Author:@imp0rtp3
Description:Unique code from Jetriz, Swid & Jeniva of the Tetris framework
Reference:https://imp0rtp3.wordpress.com/2021/08/12/tetris
Rule name:apt_CN_Tetris_JS_advanced_1
Author:@imp0rtp3 (modified by Florian Roth)
Description:Unique code from Jetriz, Swid & Jeniva of the Tetris framework
Reference:https://imp0rtp3.wordpress.com/2021/08/12/tetris
Rule name:apt_CN_Tetris_JS_simple
Author:@imp0rtp3
Description:Jetriz, Swid & Jeniva from Tetris framework signature
Reference:https://imp0rtp3.wordpress.com/2021/08/12/tetris
Rule name:SUSP_obfuscated_JS_obfuscatorio
Author:@imp0rtp3
Description:Detect JS obfuscation done by the js obfuscator (often malicious)
Reference:https://obfuscator.io
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments