MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0b2fed30ecb51f8da781148bb79ed6dc572d3f8fb36b4dc1aa017254017581e9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 0b2fed30ecb51f8da781148bb79ed6dc572d3f8fb36b4dc1aa017254017581e9
SHA3-384 hash: 0b5300fb3feb370135ff68bbc1f3191b3730126ae722674aa755f91fd22bbf5dde3276272fca90c4bfaf4c91e82ab83b
SHA1 hash: 385f03779349f9f2052670858d20143eea1fc46f
MD5 hash: 44caced027d27f8a3efee558be1848e8
humanhash: delta-nevada-north-monkey
File name:scandoc12.vbs
Download: download sample
File size:19'001 bytes
First seen:2026-07-24 12:18:37 UTC
Last seen:2026-07-24 12:37:41 UTC
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 384:KNq4EujqmRkXZPDf4nA1VPGfNOUfP7RVG2AQKXQ947WCXDqADRuzTR7Ax:KlQxSfAEgQG8HCx
TLSH T1F3829616880DBBF01A6A7557A63BB41D952C0F927C382D093B8FD1BC7B7A5348BC10A6
Magika vba
Reporter TomU
Tags:vbs

Intelligence


File Origin
# of uploads :
5
# of downloads :
60
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
vbs
First seen:
2026-07-16T09:30:00Z UTC
Last seen:
2026-07-26T08:55:00Z UTC
Hits:
~1000
Verdict:
Malware
YARA:
1 match(es)
Tags:
T1059.005 VBScript WScript.Network
Threat name:
Script-PowerShell.Packed.Generic
Status:
Suspicious
First seen:
2026-07-16 13:43:23 UTC
File Type:
Text (VBS)
AV detection:
11 of 36 (30.56%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Executes a VBScript file via the Windows Script Host.
Command and Scripting Interpreter: PowerShell
Checks computer location settings
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Visual Basic Script (vbs) vbs 0b2fed30ecb51f8da781148bb79ed6dc572d3f8fb36b4dc1aa017254017581e9

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments