VT-66db625b80c4fd0725ac10e8d59fccf81b747dfa330041196fab74261a8a
high
📛 Threat Title
VirusTotal: 66db625b80c4fd0725ac10e8d59fccf81b747dfa330041196fab74261a8aeb66
Description
VirusTotal verdict: 19 malicious / 0 suspicious of 75 engines. Suggested label: trojan.cryxos/malcode.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
66db625b80c4fd0725ac10e8d59fccf81b747dfa330041196fab74261a8aeb66
VT 19 / 75
IOC database
- Type
- hash_sha256
- Value
66db625b80c4fd0725ac10e8d59fccf81b747dfa330041196fab74261a8aeb66- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Submitted to VirusTotal for analysis.
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 19 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ALYac | malicious | JS:Trojan.Cryxos.16224 |
| Arcabit | malicious | JS:Trojan.Cryxos.D3F60 |
| Avira | malicious | TR/Malware |
| BitDefender | malicious | JS:Trojan.Cryxos.16224 |
| CTX | malicious | javascript.trojan.cryxos |
| Emsisoft | malicious | JS:Trojan.Cryxos.16224 (B) |
| ESET-NOD32 | malicious | JS/Agent.UIN trojan |
| F-Secure | malicious | Trojan.TR/Malware |
| Fortinet | malicious | JS/Agent.UIN!tr |
| GData | malicious | JS:Trojan.Cryxos.16224 |
| malicious | Detected |
|
| huorong | malicious | Trojan/JS.Runner.v |
| Kaspersky | malicious | HEUR:Trojan.Script.Generic |
| McAfeeD | malicious | Trojan:Script/Remcos.NEC |
| MicroWorld-eScan | malicious | JS:Trojan.Cryxos.16224 |
| Rising | malicious | Trojan.Obfus/JS!1.13E19 (CLASSIC) |
| Symantec | malicious | Scr.Malcode!gen |
| Varist | malicious | JS/Agent.DZM |
| VIPRE | malicious | JS:Trojan.Cryxos.16224 |
Details From VirusTotal
Basic Properties
| MD5 | f94f2b5381351541048644480c77790b |
| SHA-1 | b0cec3c5fd422806978e47dab6cbcdff9b0e9a86 |
| SHA-256 | 66db625b80c4fd0725ac10e8d59fccf81b747dfa330041196fab74261a8aeb66 |
| VHash | 6c96a08e9c64f2dbf2df2c06040f99b2 |
| SSDEEP | 768:gWc2BLpoh8ekdvbb44irfSvPO04pt932FiYWAeoxxTwpfpuWirOxYTmmc296nX6a:dBc |
| TLSH | T189E50EF7E9E9DF294C891393CDEA2FC65CD6D9AE59B29069B80CC7C13D870291432C61 |
| File type | JavaScript |
| File type tag | javascript |
| File extension | js |
| Magic | Unicode text, UTF-8 text, with CRLF line terminators |
| File size | 3.1 MB |
History
| First seen on VirusTotal | 2026-06-05 08:40 UTC |
| Last submission | 2026-06-05 08:40 UTC |
| Last analysis | 2026-06-05 08:40 UTC |
| Last modified on VirusTotal | 2026-06-05 08:46 UTC |
Known Names
PO-2606-01.js
References (1)
-
VirusTotal report
VirusTotal verdict: 19 malicious / 0 suspicious of 75 engines. Suggested label: trojan.cryxos/malcode.
Remediations (10)
-
web:chamindux.medium.com
The vote in the VirusTotal vote section indicates that a user believes the file, URL, or IP address is malicious or harmful. This helps the community by signaling potential threats and contributing to the collective understanding of the item's safety.
-
web:deephunter.readthedocs.io
The VirusTotal (VT) Hash Checker is taking a list of file hashes (MD5, SHA1, SHA256), submits them to the VirusTotal database, and outputs results in a table with links to VT, a "found" flag that indicates whether each hash is known by VT, the number of malicious detections and the number of suspicious detections.
-
web:deepwiki.com
Interpreting Results Relevant source files This document explains how to read and understand scan results from the VirusTotal Client application. It covers both the summary-level statistics and detailed engine-specific results that are displayed after scanning files or URLs. For information about initiating scans, see Scanning Files and Scanning URLs. For details about the underlying data ...
-
web:en.wikipedia.org
VirusTotal is a website created by the Spanish security company Hispasec Sistemas. Launched in June 2004, it was acquired by Google in September 2012. [1][2][3] The company's ownership switched in January 2018 to Google Security Operations, a subsidiary of Google.
-
web:github.com
Domain Threat Assessment: Analyzing Malicious Activity with VirusTotal A hands-on threat assessment using VirusTotal to uncover phishing, malware, and suspicious behavior across three domains.
-
web:mundobytes.com
Complete guide to using VirusTotal : Scan files and URLs, interpret results, and avoid false positives. Tips and uses for Google Workspace.
-
web:virustotal.github.io
VirusTotal Command Line Interface A note on Window's console If you plan to use vt-cli in Windows on a regular basis we highly recommend you avoid the standard Windows console and use Cygwin instead. The Windows console is very slow when printing large amounts of text (as vt-cli usually does) while Cygwin performs much better. Additionally, you can benefit from Cygwin's support for command ...
-
web:www.reddit.com
If I give VirusTotal the download link from Github, does it fetch the file and scan it? No, it's looking them up in the different products URL database. Unless the security company's crawlers have already downloaded that specific file, the result is just going to be the reputation of the domain.
-
web:www.techspot.com
VirusTotal is a free online service that analyzes files, URLs, and IP addresses to detect viruses, malware, and other types of threats.
-
web:www.virustotal.com
VirusTotal Assistant Bot offers a platform for users to interact with VirusTotal's threat intelligence suite and explore artifact-related information effectively.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.