MB-9361f8a732506706ce876e0d98a93b9dbe9e984da8ac683c2b2952fbe19f1a82
high
📛 Threat Title
Unknown: ADVP_34ef6dd9-b064-480d-99d0-cba2511fc2200.js
Description
File type: js. Size: 1185778 bytes. Tags: js. Reporter: lowmal3. First seen: 2026-05-15 07:26:44.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
b064-480d-99d0-cba2511fc2200.js
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/b064-480d-99d0-cba2511fc2200.js
IOC database
- Type
- domain
- Value
b064-480d-99d0-cba2511fc2200.js- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat MB-9361f8a732506706ce876e0d98a93b9dbe9e984da8ac683c2b2952fbe19f1a82
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/b064-480d-99d0-cba2511fc2200.js
hash_sha256
9361f8a732506706ce876e0d98a93b9dbe9e984da8ac683c2b2952fbe19f1a82
1 feed
IOC database
- Type
- hash_sha256
- Value
9361f8a732506706ce876e0d98a93b9dbe9e984da8ac683c2b2952fbe19f1a82- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
7c7b14b96107a917477e4296fc9984a74096c705
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/7c7b14b96107a917477e4296fc9984a74096c705
1 feed
IOC database
- Type
- hash_sha1
- Value
7c7b14b96107a917477e4296fc9984a74096c705- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/7c7b14b96107a917477e4296fc9984a74096c705
hash_md5
4358608cfad4975d49cad57d9d28c8c8
VT 33 / 75
1 feed
IOC database
- Type
- hash_md5
- Value
4358608cfad4975d49cad57d9d28c8c8- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 33 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Trojan:Multi/Generic.Gen |
| ALYac | malicious | Trojan.Generic.39962855 |
| Antiy-AVL | malicious | Trojan/Script.Agent |
| Arcabit | malicious | Trojan.Generic.D261C8E7 |
| Avast | malicious | Other:Malware-gen [Trj] |
| AVG | malicious | Other:Malware-gen [Trj] |
| Avira | malicious | TR/Malware |
| BitDefender | malicious | Trojan.Generic.39962855 |
| CTX | malicious | mp3.trojan.generic |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | JS.Starter.160 |
| Emsisoft | malicious | Trojan.Generic.39962855 (B) |
| ESET-NOD32 | malicious | Generik.DQTDLUG trojan |
| F-Secure | malicious | Trojan.TR/Malware |
| GData | malicious | Trojan.Generic.39962855 |
| malicious | Detected |
|
| huorong | malicious | Trojan/JS.Obfuscated.ff |
| Ikarus | malicious | Win32.SuspectCrc |
| Kaspersky | malicious | HEUR:Trojan.Script.Generic |
| Lionic | malicious | Trojan.Script.Generic.4!c |
| McAfeeD | malicious | ti!9361F8A73250 |
| Microsoft | malicious | Trojan:Win32/Ravartar!rfn |
| MicroWorld-eScan | malicious | Trojan.Generic.39962855 |
| NANO-Antivirus | malicious | Trojan.Script.Heuristic-js.iacgm |
| Rising | malicious | Trojan.Undefined!8.1327C (TOPIS:E0:YHpVU91h25T) |
| Sangfor | malicious | Malware.Generic-JS.Save.f0c62c9f |
| Symantec | malicious | Trojan.Gen.NPE |
| Tencent | malicious | Win32.Trojan.Malware.Dkjl |
| Varist | malicious | JS/Agent.EGM!Eldorado |
| VIPRE | malicious | Trojan.Generic.39962855 |
| VirIT | malicious | Trojan.JS.Agent.DPI |
| Xcitium | malicious | Malware@#3e6kyqm6zoi6k |
| Yandex | malicious | Trojan.Etecer.b6xF5i.10 |
Details From VirusTotal
Basic Properties
| MD5 | 4358608cfad4975d49cad57d9d28c8c8 |
| SHA-1 | 7c7b14b96107a917477e4296fc9984a74096c705 |
| SHA-256 | 9361f8a732506706ce876e0d98a93b9dbe9e984da8ac683c2b2952fbe19f1a82 |
| SSDEEP | 12288:1JS+XoxWjKgAPPf9x0zGARLMdhr6zFfEs:1cwogVUgEs |
| TLSH | T18145CA25D7EDD008F6F38E15BEB47462A837BE762E2DC91DD280054D05B290CE8B976B |
| File type | JavaScript |
| File type tag | javascript |
| File extension | js |
| Magic | Unicode text, UTF-16, little-endian text, with very long lines (5630u), with CRLF line terminators |
| File size | 1.1 MB |
History
| First seen on VirusTotal | 2026-05-15 07:28 UTC |
| Last submission | 2026-05-15 07:28 UTC |
| Last analysis | 2026-05-18 12:46 UTC |
| Last modified on VirusTotal | 2026-05-18 14:47 UTC |
Known Names
9361f8a732506706ce876e0d98a93b9dbe9e984da8ac683c2b2952fbe19f1a82.js_9361f8a732506706ce876e0d98a93b9dbe9e984da8ac683c2b2952fbe19f1a82.txtADVP_34ef6dd9-b064-480d-99d0-cba2511fc2200.jsADVPYMNT_34ef6dd9-b064-480d-99d0-cba2511fc2200.js
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: js. Size: 1185778 bytes. Tags: js. Reporter: lowmal3. First seen: 2026-05-15 07:26:44.
Remediations (10)
-
web:community.ibm.com
The CVE Process: How to Identify, Respond to, and Mitigate Vulnerabilities Author Information Author Names: Himanshu Karmarkar and Nishant Singhai Introduction As you may be aware, the number of reported CVEs has been increasing exponentially over the past few years. This surge in CVEs has left many organizations struggling to keep pace with the sheer volume of vulnerabilities, making it ...
-
web:cwe.mitre.org
private, personal information, such as personal messages, financial data, health records, geographic location, or contact details system status and environment, such as the operating system and installed packages business secrets and intellectual property network status and configuration the product's own code or internal state metadata, e.g. logging of connections or message headers indirect ...
-
web:learn.microsoft.com
Hello. Today I opened my task manager and found weird apps or files in startup apps option. "1" "a4db419f-7705-431d-afb9-940b71ea0ca4 A4db419f-7705-431d-afb9-940b71ea0ca4" Are these programs safe or is this something bad ?
-
web:www.bleepingcomputer.com
Windows Defender stuck Quarantining file - posted in Virus, Trojan, Spyware, and Malware Removal Help: I was running a scan on my system due to a (somewhat paranoid I admit) suspicion. Defender ...
-
web:www.joesandbox.com
Automated Malware Analysis - Joe Sandbox Management Report Windows Analysis Report ADVP_34ef6dd9-b064-480d-99d0-cba2511fc2200.js
-
web:www.joesandbox.com
Download ADVP_34ef6dd9-b064-480d-99d0-cba2511fc2200.js Unicode text, UTF-16, little-endian text, with very long lines (5630), with CRLF line terminators initial sample Details ... Signature Hits Behavior Group Mitre Attack Multi AV Scanner detection for submitted file AV Detection Java / VBScript file with very long strings (likely obfuscated ...
-
web:www.majorgeeks.com
Windows Defender may try to remove a virus, trojan, or other malware and return a message stating Remediation incomplete. Remediation incomplete leads one to assume that a virus, trojan or malware was found, but not removed.
-
web:www.reddit.com
example.dll was blocked by exploit Mitigation using rule" loading non-Microsoft signed binary." I'm new to Defender and need some help. I keep seeing a DLL file of an app getting blocked in the device timeline, even though it's signed. I've added the file path to the AV exclusion list, and all ASR rules are in audit mode, but it's still blocked.
-
web:www.reddit.com
If you don't have the in house staff to perform the threat analysis or threat hunting, you need a SOC. You could look at black point cyber since your are a PAX 8 customer. You currently have the detection portion of EDR, but not the analysis and remediation piece. You can't compare Symantec to Sentinel One, they aren't the same. Sentinel One IMO, is a far superior product, and in the years we ...
-
web:www.sysnative.com
Hi, as described in this thread over in the Windows 10 forum, I have a problem where Windows 10 all but goes into cardiac arrest every time I try to download after the system has been running for a couple of hours. So after trying a few solutions with no success, the mod helping me asked me to...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.