MB-9d34b9747ceb4a2a40f23df7e3f91fa3a96cac6f1931cdb2081ca5b84a81c6cc
high
📛 Threat Title
Unknown: Order-TP1026230_CBB237.js
Description
File type: js. Size: 831532 bytes. Tags: 184-95-51-188, js, spam-ita, sterlingreservewealth-info. Reporter: JAMESWT_WT. First seen: 2026-05-14 19:49:04.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
9d34b9747ceb4a2a40f23df7e3f91fa3a96cac6f1931cdb2081ca5b84a81c6cc
1 feed
IOC database
- Type
- hash_sha256
- Value
9d34b9747ceb4a2a40f23df7e3f91fa3a96cac6f1931cdb2081ca5b84a81c6cc- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
645447d36c96a09d267f25dc60b03d5c23df749e
VT 29 / 75
1 feed
IOC database
- Type
- hash_sha1
- Value
645447d36c96a09d267f25dc60b03d5c23df749e- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 29 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Trojan:Multi/Cryxos.Gen |
| ALYac | malicious | Trojan.GenericKD.80130131 |
| Antiy-AVL | malicious | Trojan/Script.Agent |
| Arcabit | malicious | Trojan.Generic.D4C6B053 |
| Avast | malicious | Other:Malware-gen [Trj] |
| AVG | malicious | Other:Malware-gen [Trj] |
| Avira | malicious | TR/Malware |
| BitDefender | malicious | Trojan.GenericKD.80130131 |
| CTX | malicious | mp3.trojan.cryxos |
| Cynet | malicious | Malicious (score: 99) |
| Emsisoft | malicious | Trojan.GenericKD.80130131 (B) |
| ESET-NOD32 | malicious | JS/Agent.UOZ trojan |
| F-Secure | malicious | Trojan.TR/Malware |
| GData | malicious | Trojan.GenericKD.80130131 |
| malicious | Detected |
|
| Ikarus | malicious | Trojan.JS.Crypt |
| Kaspersky | malicious | HEUR:Trojan.Script.Generic |
| Kingsoft | malicious | Script.Trojan.Generic.a |
| Lionic | malicious | Trojan.Script.Cryxos.4!c |
| McAfeeD | malicious | ti!9D34B9747CEB |
| Microsoft | malicious | Trojan:Win32/Malgent |
| MicroWorld-eScan | malicious | Trojan.GenericKD.80130131 |
| Rising | malicious | Trojan.Agent/JS!8.11351 (TOPIS:E0:L0SCPHaxyBT) |
| Symantec | malicious | Downloader |
| Tencent | malicious | Script.Trojan.Generic.Snkl |
| Varist | malicious | JS/Agent.EFV!Eldorado |
| VIPRE | malicious | Trojan.GenericKD.80130131 |
| VirIT | malicious | Trojan.JS.Agent.DPI |
| Yandex | malicious | Trojan.Etecer.b6xWk7.2 |
Details From VirusTotal
Basic Properties
| MD5 | 64b42256d5a1591161ee5419f72dde54 |
| SHA-1 | 645447d36c96a09d267f25dc60b03d5c23df749e |
| SHA-256 | 9d34b9747ceb4a2a40f23df7e3f91fa3a96cac6f1931cdb2081ca5b84a81c6cc |
| SSDEEP | 3072:ha1O0iVkBV0e+g2fTBPe4PYsmah3sbnWgRigNMqhitSDugxg0jdZi:w0a1OgNsmRb5RiaItSDu2k |
| TLSH | T12305F71697EA000CFDB31F90A83410BF68B6BB6A3C25D41F10A5184F6EB1E84DB76776 |
| File type | VBA |
| File type tag | vba |
| Magic | Unicode text, UTF-16, little-endian text, with very long lines (1251u), with CRLF line terminators |
| File size | 812.0 KB |
History
| First seen on VirusTotal | 2026-05-14 19:47 UTC |
| Last submission | 2026-05-15 13:02 UTC |
| Last analysis | 2026-05-20 06:04 UTC |
| Last modified on VirusTotal | 2026-05-20 08:09 UTC |
Known Names
Order-TP1026230_CBB237.js9d34b9747ceb4a2a40f23df7e3f91fa3a96cac6f1931cdb2081ca5b84a81c6cc.jss1u5twy.exe_9d34b9747ceb4a2a40f23df7e3f91fa3a96cac6f1931cdb2081ca5b84a81c6cc.txt
hash_md5
64b42256d5a1591161ee5419f72dde54
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/64b42256d5a1591161ee5419f72dde54
1 feed
IOC database
- Type
- hash_md5
- Value
64b42256d5a1591161ee5419f72dde54- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/64b42256d5a1591161ee5419f72dde54
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: js. Size: 831532 bytes. Tags: 184-95-51-188, js, spam-ita, sterlingreservewealth-info. Reporter: JAMESWT_WT. First seen: 2026-05-14 19:49:04.
Remediations (10)
-
web:community.o2.co.uk
Go to Support > Orders > Track my order > Select your mobile number. Please refer to the email sent in May for additional information. I have no affiliation whatsoever with O2 or any subsidiary companies. Comments posted are entirely of my own opinion. This is not Customer Service so we are unable to help with account specific issues.
-
web:community.o2.co.uk
Solved: hi, i received this a few minutes ago, and do not know what ut refers to: Just confirming your order has gone through - thanks. Your order
-
web:learn.microsoft.com
The details for 23rd February 2026 are - Order Number for Microsoft 365 Basic [Moderation note: PII removed] and the Bendigo Bank Transaction Number is [Moderation note: PII removed].
-
web:userapps.support.sap.com
This article provides steps to check the configuration for cases when workflow is not triggering, not reaching approvers, or not reaching user Work Inbox.
-
web:wordpress.org
The " Unknown " order origin usually happens when WooCommerce is unable to determine the source of traffic for that particular order . It could be due to various factors such as browser privacy settings, payment gateway redirections, or lack of tracking parameters.
-
web:www.amazonforum.com
Amazon Digital and Device Forum United States Loading × Sorry to interrupt CSS Error Refresh
-
web:www.chefsuccess.com
What should I do if I receive an unknown order from a customer? If you receive an unknown order , first check your order management system or platform to see if the order is linked to a specific customer.
-
web:www.reddit.com
An order of mine from tcgplayer direct was provided with a tracking number that "doesn't exist"? I made a tgplayer order 11 days ago and the tracking number they provided says, "xxxxxxxxxxxxxxx doesn't seem to be a USPS tracking number.
-
web:www.reddit.com
There are a bunch of orders on my Shop app from nextdoor.com that have shown up all of a sudden. It doesn't say what the items are, they are all new orders . Except two now, one of which has been delivered to Ottawa, ON, and the other to Normandy, France.
-
web:www.trackingmore.com
Track your orders and get accurate shipping updates from multiple carriers worldwide. Enter your tracking number now!
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.