s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

VT-66db625b80c4fd0725ac10e8d59fccf81b747dfa330041196fab74261a8a high

📛 Threat Title

VirusTotal: 66db625b80c4fd0725ac10e8d59fccf81b747dfa330041196fab74261a8aeb66

Category: ioc First seen: Last updated:

Description

VirusTotal verdict: 19 malicious / 0 suspicious of 75 engines. Suggested label: trojan.cryxos/malcode.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 66db625b80c4fd0725ac10e8d59fccf81b747dfa330041196fab74261a8aeb66 VT 19 / 75

IOC database

Type
hash_sha256
Value
66db625b80c4fd0725ac10e8d59fccf81b747dfa330041196fab74261a8aeb66
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Submitted to VirusTotal for analysis.

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 19 of 75 VirusTotal vendors

VendorVerdictDetection
ALYac malicious JS:Trojan.Cryxos.16224
Arcabit malicious JS:Trojan.Cryxos.D3F60
Avira malicious TR/Malware
BitDefender malicious JS:Trojan.Cryxos.16224
CTX malicious javascript.trojan.cryxos
Emsisoft malicious JS:Trojan.Cryxos.16224 (B)
ESET-NOD32 malicious JS/Agent.UIN trojan
F-Secure malicious Trojan.TR/Malware
Fortinet malicious JS/Agent.UIN!tr
GData malicious JS:Trojan.Cryxos.16224
Google malicious Detected
huorong malicious Trojan/JS.Runner.v
Kaspersky malicious HEUR:Trojan.Script.Generic
McAfeeD malicious Trojan:Script/Remcos.NEC
MicroWorld-eScan malicious JS:Trojan.Cryxos.16224
Rising malicious Trojan.Obfus/JS!1.13E19 (CLASSIC)
Symantec malicious Scr.Malcode!gen
Varist malicious JS/Agent.DZM
VIPRE malicious JS:Trojan.Cryxos.16224

Details From VirusTotal

Basic Properties
MD5f94f2b5381351541048644480c77790b
SHA-1b0cec3c5fd422806978e47dab6cbcdff9b0e9a86
SHA-25666db625b80c4fd0725ac10e8d59fccf81b747dfa330041196fab74261a8aeb66
VHash6c96a08e9c64f2dbf2df2c06040f99b2
SSDEEP768:gWc2BLpoh8ekdvbb44irfSvPO04pt932FiYWAeoxxTwpfpuWirOxYTmmc296nX6a:dBc
TLSHT189E50EF7E9E9DF294C891393CDEA2FC65CD6D9AE59B29069B80CC7C13D870291432C61
File typeJavaScript
File type tagjavascript
File extensionjs
MagicUnicode text, UTF-8 text, with CRLF line terminators
File size3.1 MB
History
First seen on VirusTotal2026-06-05 08:40 UTC
Last submission2026-06-05 08:40 UTC
Last analysis2026-06-05 08:40 UTC
Last modified on VirusTotal2026-06-05 08:46 UTC
Known Names
  • PO-2606-01.js

References (1)

  • VirusTotal report

    VirusTotal verdict: 19 malicious / 0 suspicious of 75 engines. Suggested label: trojan.cryxos/malcode.

Remediations (10)

  • web:chamindux.medium.com

    The vote in the VirusTotal vote section indicates that a user believes the file, URL, or IP address is malicious or harmful. This helps the community by signaling potential threats and contributing to the collective understanding of the item's safety.

  • web:deephunter.readthedocs.io

    The VirusTotal (VT) Hash Checker is taking a list of file hashes (MD5, SHA1, SHA256), submits them to the VirusTotal database, and outputs results in a table with links to VT, a "found" flag that indicates whether each hash is known by VT, the number of malicious detections and the number of suspicious detections.

  • web:deepwiki.com

    Interpreting Results Relevant source files This document explains how to read and understand scan results from the VirusTotal Client application. It covers both the summary-level statistics and detailed engine-specific results that are displayed after scanning files or URLs. For information about initiating scans, see Scanning Files and Scanning URLs. For details about the underlying data ...

  • web:en.wikipedia.org

    VirusTotal is a website created by the Spanish security company Hispasec Sistemas. Launched in June 2004, it was acquired by Google in September 2012. [1][2][3] The company's ownership switched in January 2018 to Google Security Operations, a subsidiary of Google.

  • web:github.com

    Domain Threat Assessment: Analyzing Malicious Activity with VirusTotal A hands-on threat assessment using VirusTotal to uncover phishing, malware, and suspicious behavior across three domains.

  • web:mundobytes.com

    Complete guide to using VirusTotal : Scan files and URLs, interpret results, and avoid false positives. Tips and uses for Google Workspace.

  • web:virustotal.github.io

    VirusTotal Command Line Interface A note on Window's console If you plan to use vt-cli in Windows on a regular basis we highly recommend you avoid the standard Windows console and use Cygwin instead. The Windows console is very slow when printing large amounts of text (as vt-cli usually does) while Cygwin performs much better. Additionally, you can benefit from Cygwin's support for command ...

  • web:www.reddit.com

    If I give VirusTotal the download link from Github, does it fetch the file and scan it? No, it's looking them up in the different products URL database. Unless the security company's crawlers have already downloaded that specific file, the result is just going to be the reputation of the domain.

  • web:www.techspot.com

    VirusTotal is a free online service that analyzes files, URLs, and IP addresses to detect viruses, malware, and other types of threats.

  • web:www.virustotal.com

    VirusTotal Assistant Bot offers a platform for users to interact with VirusTotal's threat intelligence suite and explore artifact-related information effectively.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.