Netskope Threat Labs

Divergent

ATP Sandbox Adv. HeuristicsAV

This generic detection identifies JavaScript based dropper and downloader malware that delivers additional payloads onto infected systems. Scripts in this class arrive through phishing emails, malvertising, and compromised websites, then fetch heavier payloads such as information stealers and remote access trojans from remote servers. Detections under this name indicate that a script executed and attempted to download follow on malware, which usually signals an intrusion chain in progress.

First seen
May 2022
Last seen
September 2026
Alert Name
GT:JS.Divergent.3.018D4EDE
GT:JS.Divergent.3.0264FBCA
GT:JS.Divergent.3.03D1BA0F
GT:JS.Divergent.3.04969D5E
GT:JS.Divergent.3.057E5DB4
GT:JS.Divergent.3.0836CFC8
GT:JS.Divergent.3.08CE81AD
GT:JS.Divergent.3.0A93C195
GT:JS.Divergent.3.0B4324C2
GT:JS.Divergent.3.0DC44C1B