MB-306b0808c0ecbf7fa74f3e7c7f712f9984494d667be7eeecd7f60a03977d3775
high
📛 Threat Title
Unknown: 306b0808c0ecbf7fa74f3e7c7f712f9984494d667be7eeecd7f60a03977d3775.js
Description
File type: unknown. Size: 2237469 bytes. Tags: 45-133-174-90. Reporter: JAMESWT_WT. First seen: 2026-05-14 07:32:22.
Indicators of Compromise (2)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
306b0808c0ecbf7fa74f3e7c7f712f9984494d667be7eeecd7f60a03977d3775
VT 27 / 75
1 feed
IOC database
- Type
- hash_sha256
- Value
306b0808c0ecbf7fa74f3e7c7f712f9984494d667be7eeecd7f60a03977d3775- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 27 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Trojan:Multi/Generic.Gen |
| ALYac | malicious | Trojan.Generic.39951337 |
| Antiy-AVL | malicious | Trojan/JS.Rescoms |
| Arcabit | malicious | Trojan.Generic.D2619BE9 |
| Avira | malicious | TR/Malware |
| BitDefender | malicious | Trojan.Generic.39951337 |
| CTX | malicious | javascript.trojan.dcrat |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | JS.Starter.162 |
| Emsisoft | malicious | Trojan.Generic.39951337 (B) |
| F-Secure | malicious | Trojan.TR/Malware |
| Fortinet | malicious | JS/Rescoms.B!tr |
| GData | malicious | Trojan.Generic.39951337 |
| malicious | Detected |
|
| Ikarus | malicious | Trojan.Malware |
| Kaspersky | malicious | UDS:Backdoor.Win32.DcRat |
| Lionic | malicious | Trojan.Script.Generic.4!c |
| McAfeeD | malicious | Trojan:Script/Remcos.NEC |
| MicroWorld-eScan | malicious | Trojan.Generic.39951337 |
| Sophos | malicious | JS/DwnLdr-ADKP |
| Symantec | malicious | Trojan Horse |
| Tencent | malicious | Script.Trojan.Generic.Ychl |
| TrendMicro-HouseCall | malicious | Backdoor.JS.DCRAT.YXGEKZ |
| Varist | malicious | JS/Agent.DZM |
| VIPRE | malicious | Trojan.Generic.39951337 |
| VirIT | malicious | Trojan.JS.Agent.JQO |
| ZoneAlarm | malicious | JS/DwnLdr-ADKP |
Details From VirusTotal
Basic Properties
| MD5 | dc53cb749a12779865c49cf5d23b5647 |
| SHA-1 | f632f93573c3a19fe4086854044277d5249068ca |
| SHA-256 | 306b0808c0ecbf7fa74f3e7c7f712f9984494d667be7eeecd7f60a03977d3775 |
| VHash | 2094bdd8cd98fa9b0bd1bd36b8ddb789 |
| SSDEEP | 96:8NKDTqkugKqY/TG3tGqV0jrHXOWqJ14sEUqHkQcQgluqMGlhNYzCxrzpzUe841nH:T/5cjFyt |
| TLSH | T17BA54EE55EB3D0D90280D2972D2DB05CC74E140D66069CAB1CDC9EFC581B8D9A6AFCBB |
| File type | JavaScript |
| File type tag | javascript |
| File extension | js |
| Magic | CSV text |
| File size | 2.1 MB |
History
| First seen on VirusTotal | 2026-05-11 17:57 UTC |
| Last submission | 2026-05-11 23:52 UTC |
| Last analysis | 2026-05-20 09:57 UTC |
| Last modified on VirusTotal | 2026-05-20 12:02 UTC |
Known Names
306b0808c0ecbf7fa74f3e7c7f712f9984494d667be7eeecd7f60a03977d3775.jsConfidencial_Urgente_Caso_11_Mayo_2026.docx.jsACUTARIO DE DEMNADA CONTRA.jssleestak_payload_1.js
hash_md5
dc53cb749a12779865c49cf5d23b5647
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/dc53cb749a12779865c49cf5d23b5647
2 feeds
IOC database
- Type
- hash_md5
- Value
dc53cb749a12779865c49cf5d23b5647- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/dc53cb749a12779865c49cf5d23b5647
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: unknown. Size: 2237469 bytes. Tags: 45-133-174-90. Reporter: JAMESWT_WT. First seen: 2026-05-14 07:32:22.
Remediations (10)
-
web:askubuntu.com
9 Update: Kernel 6.8.-117.117 is released now and features a kernel-level fix for CVE-2026-31431. While the website may be down, the security email list continues to work apparently and they have emailed about a mitigation there in an email from 30.04.2026 18:06 CET. The issue should be mitigated for now thanks to USN-8226-1 and USN-8226-2.
-
web:patchmypc.com
Clients stuck in unknown ? Use these steps to troubleshoot and validate update state in SCCM.
-
web:techcommunity.microsoft.com
In the interim we have implemented a SCCM CI for detection of anything other than a KMS key and then a remediation to KMS if required. This does temporarily change the Windows edition and allow the policy to apply (and hopefully any future cert updates), but does mean that the CI needs to run every day as the device still reverts to Pro OEM ...
-
web:unit42.paloaltonetworks.com
Remediation playbooks: Actionable guidance for rotating credentials and purging malicious dependencies from local and cloud-based caches Shai-Hulud: A New Wave A malicious npm package published as @bitwarden/cli version 2026.4.0 was identified as part of a broader supply-chain campaign attributed to TeamPCP.
-
web:www.17track.net
Enter your tracking number to track Unknown packages and get real-time updates on delivery status. Discover more about FQAs in this guide on Unknown tracking.
-
web:www.manageengine.com
Steps to follow when software deployment fails due to unknown error code.
-
web:www.reddit.com
Pulling my hair out for this one. What's happening- When I deploy a VPP app (Microsoft Teams for example) and scope it to all users with user license…
-
web:www.thewindowsclub.com
Learn how to identify and fix Unknown Device in Device Manager of Windows 11/10. Use Unknown Device Identifier to troubleshoot a device listed as Unknown Device Driver.
-
web:www.toolsley.com
Free browser tool to identify unknown files based on their contents. Recognizes over 2000 file formats using libmagic. No installation necessary. Just drag & drop!
-
web:www.windowsdigitals.com
Can't install or run an app from unknown publisher? Here's how to allow unknown publisher in Windows 11/10, and how to disable the warning.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.