🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 100f0ffd73a011ade58e81ed08f79c59a3ed986101be94ca2718f3a4e84556b0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 100f0ffd73a011ade58e81ed08f79c59a3ed986101be94ca2718f3a4e84556b0
SHA3-384 hash: 42f829c3a97421269633dc4ac9c16508a5262d1f6c36191b98959c0fa5157851d8438d5f21479c04b1f1e81d0fd1d1d7
SHA1 hash: cb8392a89735a7c70581f5f14302ce05016edc7b
MD5 hash: fd598a723a8fb1c5ab7b1a58db5fbd74
humanhash: mango-eleven-green-cat
File name:MG6UIMA6.vbs
Download: download sample
File size:25'152 bytes
First seen:2026-04-23 01:25:51 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/html
ssdeep 384:oy2unDdtFVkGFk5CftjmFBs/RecofBp+I65IvLmO0AZJgTchh9firgZXX0GCfira:oS
TLSH T179B26C2C09BDFA5D93D9E217EA95F3236D4A5CAFC2B975132AF34C6960024C045EB4C7
Magika html
Reporter BastianHein
Tags:vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
23
Origin country :
CL CL
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
base64 obfuscated powershell
Verdict:
Malicious
File Type:
hta
First seen:
2026-04-22T22:40:00Z UTC
Last seen:
2026-04-23T18:45:00Z UTC
Hits:
~10
Gathering data
Gathering data
Threat name:
Script-WScript.Trojan.Electryon
Status:
Malicious
First seen:
2026-04-23 00:43:48 UTC
File Type:
Text (VBS)
AV detection:
10 of 36 (27.78%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Contacts third-party web service commonly abused for C2
Checks computer location settings
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments