s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

URLhaus-PL-232358a4d9adc55b37b1c82106276157b0ffc0e1ca2a6707a715cb4b5e503293 medium

📛 Threat Title

URLhaus payload: (js) 232358a4d9adc55b…

Category: malware Published: Source updated: First seen: Last updated: Source: URLhaus

Description

File type: js. Size: 158,480 bytes. First seen: 2026-05-15 12:31:23.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 232358a4d9adc55b37b1c82106276157b0ffc0e1ca2a6707a715cb4b5e503293 VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/232358a4d9adc55b37b1c82106276157b0ffc0e1ca2a6707a715cb4b5e503293

IOC database

Type
hash_sha256
Value
232358a4d9adc55b37b1c82106276157b0ffc0e1ca2a6707a715cb4b5e503293
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
URLhaus payload hash

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/232358a4d9adc55b37b1c82106276157b0ffc0e1ca2a6707a715cb4b5e503293

hash_md5 e5a1c632a7d535fb7b5701fb70eb7757

IOC database

Type
hash_md5
Value
e5a1c632a7d535fb7b5701fb70eb7757
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
URLhaus payload hash

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_ssdeep 3072:zismtbttnrvoqrjmjehdhwu5wuszjkoty4dm/vwdf683ejadfxx:zatwpdfh

IOC database

Type
hash_ssdeep
Value
3072:zismtbttnrvoqrjmjehdhwu5wuszjkoty4dm/vwdf683ejadfxx:zatwpdfh
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
ssdeep of URLhaus payload 232358a4d9adc55b…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_tlsh t140f3c7818cb6dd072dc47bbd7c9a6e021fca538275f04907ba34569836b49be31da2

IOC database

Type
hash_tlsh
Value
t140f3c7818cb6dd072dc47bbd7c9a6e021fca538275f04907ba34569836b49be31da2
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
TLSH of URLhaus payload 232358a4d9adc55b…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

Remediations (10)

  • web:cheatsheetseries.owasp.org

    Clickjacking Defense Cheat Sheet Introduction This cheat sheet is intended to provide guidance for developers on how to defend against Clickjacking, also known as UI redress attacks. There are three main mechanisms that can be used to defend against these attacks: Preventing the browser from loading the page in frame using the X-Frame-Options or Content Security Policy (frame-ancestors) HTTP ...

  • web:docs.infoblox.com

    { "matches": [ { "ioc_value": "103.150.68.124:449", "ioc_type": "ip:port", "threat_type": "botnet_cc", "malware": "win.trickbot", "malware_alias": "Trickster,TheTrick ...

  • web:docs.spamhaus.com

    A payload gets observed in combination with a URL tracked by URLhaus ; The information on a payload changes for a URL tracked by URLhaus (e.g. malware family associated with a payload ). URL Additions This message gets triggered when a new URL gets reported (and subsequently added) to the URLhaus database. The message has the following format:

  • web:github.com

    URLhaus is an open platform for sharing malware distribution sites. This repository provides some sample python3 scripts on how to interact with the URLhaus bulk API.

  • web:public-api.org

    Support & Documentation Is the URLhaus API secure? Yes, the URLhaus API uses HTTPS encryption to secure all data in transit. All API requests and responses are encrypted.

  • web:publicapis.io

    Bulk queries and Download Malware Samples Get API details, uptime stats, pricing info, and integration examples for URLhaus .

  • web:trojanhorsejs.readthedocs.io

    Enterprise-grade threat intelligence library for JavaScript Feeds API Complete API reference for TrojanHorse. js threat intelligence feeds, including URLhaus , VirusTotal, AlienVault OTX, AbuseIPDB, and CrowdSec CTI integrations. Overview The Feeds API provides standardized interfaces for integrating with multiple threat intelligence sources, enabling real-time threat detection, correlation, and ...

  • web:urlhaus.abuse.ch

    URLhaus URLhaus is a platform from abuse.ch and Spamhaus dedicated to sharing malicious URLs that are being used for malware distribution. Report URLs and explore the database for valuable intelligence. Use the APIs, to seamlessly push and pull signals, and automate bulk queries. With this intelligence, gain insights into malware behavior, to help identify, track, and mitigate against malware ...

  • web:www.powershellgallery.com

    Use with parameter URL or Payload . To prevent unecessary stress for the online URLhaus API, this parameter defines the time previously retrieved data from the same API endpoint remains cached

  • web:xsoar.pan.dev

    URLhaus is a platform from abuse.ch and Spamhaus dedicated to sharing malicious URLs that are being used for malware distribution. For more information, visit: https:// urlhaus .abuse.ch/ Fetch indicators from URLhaus api Fetch indicators from the URLhaus API.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.