s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-9d34b9747ceb4a2a40f23df7e3f91fa3a96cac6f1931cdb2081ca5b84a81c6cc high

📛 Threat Title

Unknown: Order-TP1026230_CBB237.js

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: js. Size: 831532 bytes. Tags: 184-95-51-188, js, spam-ita, sterlingreservewealth-info. Reporter: JAMESWT_WT. First seen: 2026-05-14 19:49:04.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 9d34b9747ceb4a2a40f23df7e3f91fa3a96cac6f1931cdb2081ca5b84a81c6cc 1 feed

IOC database

Type
hash_sha256
Value
9d34b9747ceb4a2a40f23df7e3f91fa3a96cac6f1931cdb2081ca5b84a81c6cc
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 645447d36c96a09d267f25dc60b03d5c23df749e VT 29 / 75 1 feed

IOC database

Type
hash_sha1
Value
645447d36c96a09d267f25dc60b03d5c23df749e
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Flagged by 29 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious Trojan:Multi/Cryxos.Gen
ALYac malicious Trojan.GenericKD.80130131
Antiy-AVL malicious Trojan/Script.Agent
Arcabit malicious Trojan.Generic.D4C6B053
Avast malicious Other:Malware-gen [Trj]
AVG malicious Other:Malware-gen [Trj]
Avira malicious TR/Malware
BitDefender malicious Trojan.GenericKD.80130131
CTX malicious mp3.trojan.cryxos
Cynet malicious Malicious (score: 99)
Emsisoft malicious Trojan.GenericKD.80130131 (B)
ESET-NOD32 malicious JS/Agent.UOZ trojan
F-Secure malicious Trojan.TR/Malware
GData malicious Trojan.GenericKD.80130131
Google malicious Detected
Ikarus malicious Trojan.JS.Crypt
Kaspersky malicious HEUR:Trojan.Script.Generic
Kingsoft malicious Script.Trojan.Generic.a
Lionic malicious Trojan.Script.Cryxos.4!c
McAfeeD malicious ti!9D34B9747CEB
Microsoft malicious Trojan:Win32/Malgent
MicroWorld-eScan malicious Trojan.GenericKD.80130131
Rising malicious Trojan.Agent/JS!8.11351 (TOPIS:E0:L0SCPHaxyBT)
Symantec malicious Downloader
Tencent malicious Script.Trojan.Generic.Snkl
Varist malicious JS/Agent.EFV!Eldorado
VIPRE malicious Trojan.GenericKD.80130131
VirIT malicious Trojan.JS.Agent.DPI
Yandex malicious Trojan.Etecer.b6xWk7.2

Details From VirusTotal

Basic Properties
MD564b42256d5a1591161ee5419f72dde54
SHA-1645447d36c96a09d267f25dc60b03d5c23df749e
SHA-2569d34b9747ceb4a2a40f23df7e3f91fa3a96cac6f1931cdb2081ca5b84a81c6cc
SSDEEP3072:ha1O0iVkBV0e+g2fTBPe4PYsmah3sbnWgRigNMqhitSDugxg0jdZi:w0a1OgNsmRb5RiaItSDu2k
TLSHT12305F71697EA000CFDB31F90A83410BF68B6BB6A3C25D41F10A5184F6EB1E84DB76776
File typeVBA
File type tagvba
MagicUnicode text, UTF-16, little-endian text, with very long lines (1251u), with CRLF line terminators
File size812.0 KB
History
First seen on VirusTotal2026-05-14 19:47 UTC
Last submission2026-05-15 13:02 UTC
Last analysis2026-05-20 06:04 UTC
Last modified on VirusTotal2026-05-20 08:09 UTC
Known Names
  • Order-TP1026230_CBB237.js
  • 9d34b9747ceb4a2a40f23df7e3f91fa3a96cac6f1931cdb2081ca5b84a81c6cc.js
  • s1u5twy.exe
  • _9d34b9747ceb4a2a40f23df7e3f91fa3a96cac6f1931cdb2081ca5b84a81c6cc.txt
hash_md5 64b42256d5a1591161ee5419f72dde54 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/64b42256d5a1591161ee5419f72dde54
1 feed

IOC database

Type
hash_md5
Value
64b42256d5a1591161ee5419f72dde54
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/64b42256d5a1591161ee5419f72dde54

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: js. Size: 831532 bytes. Tags: 184-95-51-188, js, spam-ita, sterlingreservewealth-info. Reporter: JAMESWT_WT. First seen: 2026-05-14 19:49:04.

Remediations (10)

  • web:community.o2.co.uk

    Go to Support > Orders > Track my order > Select your mobile number. Please refer to the email sent in May for additional information. I have no affiliation whatsoever with O2 or any subsidiary companies. Comments posted are entirely of my own opinion. This is not Customer Service so we are unable to help with account specific issues.

  • web:community.o2.co.uk

    Solved: hi, i received this a few minutes ago, and do not know what ut refers to: Just confirming your order has gone through - thanks. Your order

  • web:learn.microsoft.com

    The details for 23rd February 2026 are - Order Number for Microsoft 365 Basic [Moderation note: PII removed] and the Bendigo Bank Transaction Number is [Moderation note: PII removed].

  • web:userapps.support.sap.com

    This article provides steps to check the configuration for cases when workflow is not triggering, not reaching approvers, or not reaching user Work Inbox.

  • web:wordpress.org

    The " Unknown " order origin usually happens when WooCommerce is unable to determine the source of traffic for that particular order . It could be due to various factors such as browser privacy settings, payment gateway redirections, or lack of tracking parameters.

  • web:www.amazonforum.com

    Amazon Digital and Device Forum United States Loading × Sorry to interrupt CSS Error Refresh

  • web:www.chefsuccess.com

    What should I do if I receive an unknown order from a customer? If you receive an unknown order , first check your order management system or platform to see if the order is linked to a specific customer.

  • web:www.reddit.com

    An order of mine from tcgplayer direct was provided with a tracking number that "doesn't exist"? I made a tgplayer order 11 days ago and the tracking number they provided says, "xxxxxxxxxxxxxxx doesn't seem to be a USPS tracking number.

  • web:www.reddit.com

    There are a bunch of orders on my Shop app from nextdoor.com that have shown up all of a sudden. It doesn't say what the items are, they are all new orders . Except two now, one of which has been delivered to Ottawa, ON, and the other to Normandy, France.

  • web:www.trackingmore.com

    Track your orders and get accurate shipping updates from multiple carriers worldwide. Enter your tracking number now!

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.