Open-source atomic malware analysis

Analyze another

39c1ee41196d067d7f6ecc9d30e813ac5946f8c63dc4175948770967c74ba592.js

JAVASCRIPT
Verdict: HOSTILE
Mal-ecule
O(As₂)H₂(DbPo)
Size 928.8 KB download
First seen 89 days ago
Analyzed 89 days ago

Well-known

component severity, 95% confident.
lib eval/new Function call (flatted tamper fragment)

Objectives

suspicious severity, 88% confident.
anti-static/obfuscation/code-metrics Multiple source lines exceed 1000 chars
suspicious severity, 90% confident.
anti-static/obfuscation/eval Immediate invocation of new Function
component severity, 92% confident.
anti-static/obfuscation/encoding Regex component marker
component severity, 88% confident.
supply-chain/hidden-payload Single-line packed JavaScript loader profile

Micro-behaviors

notable severity, 90% confident.
data/source/dynamic Immediate new Function invocation pattern
notable severity, 70% confident.
process/interpreter JavaScript new Function constructor
baseline severity, 70% confident.
data/source/syntax Function constructor keyword
component severity, 70% confident.
data/encode String.fromCharCode() assembly

Metadata

baseline severity, 100% confident.
lang/encoded JavaScript file basename
component severity, 90% confident.
file/text File has 30 or more lines

Identity

SHA-256 39c1ee41196d067d7f6ecc9d30e813ac5946f8c63dc4175948770967c74ba592
Filename 39c1ee41196d067d7f6ecc9d30e813ac5946f8c63dc4175948770967c74ba592.js

Origin

Source harvest

Timeline

First seen 17 May 2026 14:59 UTC
First analyzed 17 May 2026 15:03 UTC
Last analyzed 17 May 2026 15:03 UTC
Last updated 17 May 2026 15:03 UTC

Labeling

Label bad
Label source harvest
Traits version 60127