Local reference
Suspicious dependency
Inferred
Mal-ecule
O(Ca)H(U)
Objectives
notable severity, 90% confident.
credential-access/capture
Reads DOM credential field values
component severity, 86% confident.
execution/lure
Regex component marker
component severity, 75% confident.
lateral-movement/social-engineering
Inline password token in lure
component severity, 75% confident.
supply-chain/recon-exfil
HTTP upload request call token
Micro-behaviors
notable severity, 82% confident.
ui/window/manage
Password input form field
baseline severity, 90% confident.
communications/http
HTTP protocol prefix
component severity, 82% confident.
crypto/symmetric/aes
JavaScript static key string assignment
component severity, 84% confident.
data/text/keywords
password/token/api_key field keyword
component severity, 84% confident.
fs/path
Hidden directory path literal
Metadata
baseline severity, 100% confident.
lang
javascript code embedded in string
component severity, 90% confident.
file/text
File has 30 or more lines
Identity
| SHA-256 | c7ff4bc86bbd1f2c5b68ea8cd4b467f0723ce030cc5e7e8c6fe73daa2347a2c8 |
|---|---|
| Filename | VirusShare_9a54983f21ec2685c54c86784a3cf1c2 |
Origin
| Source | harvest |
|---|
Timeline
| First seen | 31 May 2026 22:44 UTC |
|---|---|
| First analyzed | 2 Jun 2026 03:48 UTC |
| Last analyzed | 2 Jun 2026 03:48 UTC |
| Last updated | 2 Jun 2026 03:48 UTC |
Labeling
| Label | bad |
|---|---|
| Label source | harvest |
| Traits version | ed903 |
Not seeing what you expected? Let us know