MB-9c1e3ba57ab66359898eba3723c4ca47381ed12da5a1f0b9e946fb0882811e7f
high
📛 Threat Title
Unknown: 9c1e3ba57ab66359898eba3723c4ca47381ed12da5a1f0b9e946fb0882811e7f.js
Description
File type: js. Size: 22360 bytes. Tags: 45-133-174-90, js. Reporter: JAMESWT_WT. First seen: 2026-05-14 07:19:25.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
9c1e3ba57ab66359898eba3723c4ca47381ed12da5a1f0b9e946fb0882811e7f
VT 23 / 75
1 feed
IOC database
- Type
- hash_sha256
- Value
9c1e3ba57ab66359898eba3723c4ca47381ed12da5a1f0b9e946fb0882811e7f- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 23 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Trojan[downloader]:Win/Wacatac.C9nj |
| Arcabit | malicious | CMD:Heur.BZC.PZQ.Pantera.140.3FC900DF |
| Avast | malicious | Script:SNH-gen [Drp] |
| AVG | malicious | Script:SNH-gen [Drp] |
| Avira | malicious | DR/SNH |
| BitDefender | malicious | CMD:Heur.BZC.PZQ.Pantera.140.3FC900DF |
| CTX | malicious | powershell.unknown.pantera |
| Cynet | malicious | Malicious (score: 99) |
| Emsisoft | malicious | CMD:Heur.BZC.PZQ.Pantera.140.3FC900DF (B) |
| ESET-NOD32 | malicious | PowerShell/TrojanDownloader.Agent.QCP trojan |
| F-Secure | malicious | Dropper.DR/SNH |
| Fortinet | malicious | PowerShell/Agent.QCP!tr |
| GData | malicious | CMD:Heur.BZC.PZQ.Pantera.140.3FC900DF |
| malicious | Detected |
|
| Ikarus | malicious | Trojan-Downloader.PS.Agent |
| Lionic | malicious | Trojan.Script.Pantera.4!c |
| McAfeeD | malicious | ti!9C1E3BA57AB6 |
| Microsoft | malicious | Trojan:Script/Wacatac.B!ml |
| MicroWorld-eScan | malicious | CMD:Heur.BZC.PZQ.Pantera.140.3FC900DF |
| Symantec | malicious | Scr.Malcode!gen |
| Tencent | malicious | Win32.Trojan-Downloader.Downloader.Rnkl |
| Varist | malicious | ABApplication.IHI |
| VIPRE | malicious | CMD:Heur.BZC.PZQ.Pantera.140.3FC900DF |
Details From VirusTotal
Basic Properties
| MD5 | e1b537607709c50323d5dc4c18da5356 |
| SHA-1 | 18360ff3c7a3df370bb4c90c354bc22c2160b117 |
| SHA-256 | 9c1e3ba57ab66359898eba3723c4ca47381ed12da5a1f0b9e946fb0882811e7f |
| SSDEEP | 384:AqggYq2DfxOenGr8nDfxnDfxfwr8unar80dsxDfx5nCnvSGdsGSFSCLfW5U:Tp2bsQGrybdbZwrHar9Cxb3onCt |
| TLSH | T12AA2BFAD3CB35FA80F94DCEBC5773E4AF536A09AC0185EE6B521871612209447C27C9F |
| File type | Powershell |
| File type tag | powershell |
| File extension | ps1 |
| Magic | ASCII text, with very long lines (3489u), with CRLF line terminators |
| File size | 21.8 KB |
History
| First seen on VirusTotal | 2026-05-13 20:27 UTC |
| Last submission | 2026-05-14 16:48 UTC |
| Last analysis | 2026-05-14 07:20 UTC |
| Last modified on VirusTotal | 2026-05-16 19:42 UTC |
Known Names
9c1e3ba57ab66359898eba3723c4ca47381ed12da5a1f0b9e946fb0882811e7f.js_9c1e3ba57ab66359898eba3723c4ca47381ed12da5a1f0b9e946fb0882811e7f.txtsleestak_payload_1.ps1
hash_sha1
18360ff3c7a3df370bb4c90c354bc22c2160b117
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/18360ff3c7a3df370bb4c90c354bc22c2160b117
2 feeds
IOC database
- Type
- hash_sha1
- Value
18360ff3c7a3df370bb4c90c354bc22c2160b117- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/18360ff3c7a3df370bb4c90c354bc22c2160b117
hash_md5
e1b537607709c50323d5dc4c18da5356
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/e1b537607709c50323d5dc4c18da5356
2 feeds
IOC database
- Type
- hash_md5
- Value
e1b537607709c50323d5dc4c18da5356- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/e1b537607709c50323d5dc4c18da5356
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: js. Size: 22360 bytes. Tags: 45-133-174-90, js. Reporter: JAMESWT_WT. First seen: 2026-05-14 07:19:25.
Remediations (10)
-
web:community.cisco.com
This works very fine (auto remediation with AMP retropsective alert) but I have an issue with Remediate Messages in the Mailboxes from SMA with error seen SMA Remediation Logs: Thu Sep 29 17:36:32 2022 Warning: Remediation failed for MID (s): 6901105 initiated as part of batch test remediation 1. Reason: Unknown Token Error 400 (Host 192.168.X.X)
-
web:learn.microsoft.com
Nessus finding on windows server 2012 r2 51192 - SSL Certificate Cannot Be Trusted . The following certificate was at the top of the certificate chain sent by the remote host, but it is signed by an unknown certificate authority : |-Subject :…
-
web:stackoverflow.com
We have an issue in our solution (we are using .net core) and the SNYK vulnerabilities scaner show us that we have a Server-Side Request Forgery (SSRF) vulnerability in the next code at the : public
-
web:support.apple.com
If you try to open an app by an unknown developer and you see a warning dialog on your Mac, you can override your security settings to open it.
-
web:www.17track.net
Enter your tracking number to track Unknown packages and get real-time updates on delivery status. Discover more about FQAs in this guide on Unknown tracking.
-
web:www.crowdstrike.com
NPM is the package manager for the Node.js JavaScript platform, which allows developers to share and manage JavaScript libraries and tools. By compromising these packages, attackers are able to perform supply chain attacks that have widespread impact and can be challenging to identify.
-
web:www.reddit.com
This behavior happens randomly with some of our customers every time you have to accept new T&C in ABM. Seems like connection between Intune and ABM is broken. It often helps to just renew both tokens, perform sync and maybe wait a day. In some cases we had to deploy a new ADE token, but VPP was working after just renewing the token.
-
web:www.reddit.com
Pulling my hair out for this one. What's happening- When I deploy a VPP app (Microsoft Teams for example) and scope it to all users with user license…
-
web:www.reddit.com
The file name was Trojan:JS/Phish.SM!MTB and it was found inside this path: C:\Users\xxxx\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Service Worker\CacheStorage\e9b4fd7ee1e18004388061ab7eb20fe356c5b530\08e423bf-8d38-46e9-85d9-c7e461aea457\2e670509c7966d26_0 I haven't downloaded anything sus or anything similar.
-
web:www.wiz.io
A compromised axios maintainer account led to malicious npm releases. Learn how to assess impact, detect compromise, and secure your development workflows.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.