VT-f94f2b5381351541048644480c77790b
medium
📛 Threat Title
File hash (MD5): f94f2b5381351541048644480c77790b
Description
Hash IOC ingested from threat-intel feed 'Abuse.ch'. See VirusTotal for vendor verdicts, file metadata, sandbox behaviour, and relationships (contacted IPs / domains / URLs, dropped files, etc.). Feed description: MD5 hashes: Recent additions
Remediations (10)
-
web:check.town
Free file hash checker. Upload a file and compute MD5 , SHA-1, SHA-256, and SHA-512 checksums client-side.
-
web:emn178.github.io
This MD5 online tool helps you calculate the hash of a file from local or URL using MD5 without uploading the file . It also supports HMAC.
-
web:flipperfile.com
Free MD5 hash checker that works entirely in your browser. Generate and compare MD5 hashes for text or files instantly, with no uploads or tracking.
-
web:freetoolkit.co
Free File Hash Checker online — instantly verify file integrity directly in your browser. Calculate MD5 , SHA-1, SHA-256, and SHA-512 checksums without uploading your file . 100% private.
-
web:inventivehq.com
File Hash Checker & Malware Hash Lookup Drag in a file to hash it locally (SHA-256/SHA-1, nothing uploaded), or paste MD5 /SHA-1/SHA-256 hashes — single or in bulk — and check them against known malware with VirusTotal & MalwareBazaar deep-links.
-
web:miniwebtool.com
MD5 Hash Generator - Generate MD5 hash from text or files instantly. Supports multiple output formats including hex and Base64. Verify hashes and check file integrity online.
-
web:sslinsights.com
Learn how to get MD5 hash of a file in Windows using Command Prompt and PowerShell. Quick and easy methods for file verification.
-
web:www.freecodeformat.com
Verify file integrity online. Calculate MD5 , SHA1, SHA256, SHA512, SHA3, RIPEMD-160, and CRC32 hashes for any file . Fast, secure, and supports multiple files .
-
web:www.getzenquery.com
Verify file integrity instantly with our free online File Hash Checker. Upload any file to compute MD5 , SHA-1, SHA-256, and SHA-512 hashes—then compare with original or expected checksums. Perfect for ensuring downloaded files are intact, validating software authenticity, or detecting corruption. All processing happens locally in your browser for privacy.
-
web:www.toolsley.com
Calculate the hash for any file online. Generate MD5 , SHA1, SHA256 or CRC32 instantly in your browser using JavaScript. Make share-able links to validate files . No need to install anything, just drag & drop.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_md5
f94f2b5381351541048644480c77790b
VT 19 / 75
1 feed
IOC database
- Type
- hash_md5
- Value
f94f2b5381351541048644480c77790b- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Imported from threat-intel feed: Abuse.ch
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 19 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ALYac | malicious | JS:Trojan.Cryxos.16224 |
| Arcabit | malicious | JS:Trojan.Cryxos.D3F60 |
| Avira | malicious | TR/Malware |
| BitDefender | malicious | JS:Trojan.Cryxos.16224 |
| CTX | malicious | javascript.trojan.cryxos |
| Emsisoft | malicious | JS:Trojan.Cryxos.16224 (B) |
| ESET-NOD32 | malicious | JS/Agent.UIN trojan |
| F-Secure | malicious | Trojan.TR/Malware |
| Fortinet | malicious | JS/Agent.UIN!tr |
| GData | malicious | JS:Trojan.Cryxos.16224 |
| malicious | Detected |
|
| huorong | malicious | Trojan/JS.Runner.v |
| Kaspersky | malicious | HEUR:Trojan.Script.Generic |
| McAfeeD | malicious | Trojan:Script/Remcos.NEC |
| MicroWorld-eScan | malicious | JS:Trojan.Cryxos.16224 |
| Rising | malicious | Trojan.Obfus/JS!1.13E19 (CLASSIC) |
| Symantec | malicious | Scr.Malcode!gen |
| Varist | malicious | JS/Agent.DZM |
| VIPRE | malicious | JS:Trojan.Cryxos.16224 |
Details From VirusTotal
Basic Properties
| MD5 | f94f2b5381351541048644480c77790b |
| SHA-1 | b0cec3c5fd422806978e47dab6cbcdff9b0e9a86 |
| SHA-256 | 66db625b80c4fd0725ac10e8d59fccf81b747dfa330041196fab74261a8aeb66 |
| VHash | 6c96a08e9c64f2dbf2df2c06040f99b2 |
| SSDEEP | 768:gWc2BLpoh8ekdvbb44irfSvPO04pt932FiYWAeoxxTwpfpuWirOxYTmmc296nX6a:dBc |
| TLSH | T189E50EF7E9E9DF294C891393CDEA2FC65CD6D9AE59B29069B80CC7C13D870291432C61 |
| File type | JavaScript |
| File type tag | javascript |
| File extension | js |
| Magic | Unicode text, UTF-8 text, with CRLF line terminators |
| File size | 3.1 MB |
History
| First seen on VirusTotal | 2026-06-05 08:40 UTC |
| Last submission | 2026-06-05 08:40 UTC |
| Last analysis | 2026-06-05 08:40 UTC |
| Last modified on VirusTotal | 2026-06-05 08:46 UTC |
Known Names
PO-2606-01.js
References (1)
-
VirusTotal report
Vendor verdicts, file metadata, sandbox behaviour, and relationships (contacted IPs / domains / URLs, execution parents, dropped files).
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.