🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1079ddd38cd9d74ad13e254ff709932bd97dd3907ca00bba368382f64a6f6e87. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ConnectWise


Vendor detections: 11


Intelligence 11 IOCs YARA 1 File information Comments

SHA256 hash: 1079ddd38cd9d74ad13e254ff709932bd97dd3907ca00bba368382f64a6f6e87
SHA3-384 hash: 27b892d03acfd2440f5d3e7d9128dc649905dc0544af0d6bfd321b2c58654f9b14c0004c5b42919ad30d794daf9c4ba6
SHA1 hash: 443def3817da419526006ce5b21023ecbe7fb679
MD5 hash: 51e241db4a872728b183dc3c2e0c1522
humanhash: pip-seventeen-mike-august
File name:Statement_Viewer.vbs
Download: download sample
Signature ConnectWise
File size:1'778 bytes
First seen:2026-04-20 15:00:37 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 24:cSdEPK2hNcRiE5d3s39A18bzOMa7Am/30qQhYY7toLgIMaFONX8za3h3OQ0F652A:cXNcIE0NA1dAm/ujouNmaxO765T
TLSH T10E31010FAD06D361497249A74764AC1ECAE1153709618148BB54C88A4F3667FFBE80FE
Magika vba
Reporter cocaman
Tags:ConnectWise vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
84
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
91.7%
Tags:
shellcode dropper spawn
Gathering data
Verdict:
Malicious
File Type:
vbs
First seen:
2026-04-16T15:38:00Z UTC
Last seen:
2026-04-22T07:40:00Z UTC
Hits:
~100
Detections:
Trojan-Downloader.JS.SLoad.sb PDM:Trojan.Win32.Generic HEUR:Trojan-Downloader.VBS.SLoad.gen not-a-virus:RemoteAdmin.MSIL.ConnectWise.c not-a-virus:RemoteAdmin.MSIL.ConnectWise.b not-a-virus:RemoteAdmin.MSIL.ConnectWise.a not-a-virus:HEUR:RemoteAdmin.MSIL.ConnectWise.gen not-a-virus:RemoteAdmin.MSIL.ConnectWise.d
Result
Threat name:
ScreenConnect Tool
Detection:
malicious
Classification:
evad
Score:
100 / 100
Signature
.NET source code references suspicious native API functions
Changes security center settings (notifications, updates, antivirus, firewall)
Contains functionality to hide user accounts
Creates files in the system32 config directory
Enables network access during safeboot for specific services
Joe Sandbox ML detected suspicious sample
Modifies security policies related information
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Potential malicious VBS script found (has network functionality)
Potential malicious VBS script found (suspicious strings)
Reads the Security eventlog
Reads the System eventlog
Sigma detected: Script Initiated Connection to Non-Local Network
Sigma detected: WScript or CScript Dropper
System process connects to network (likely due to code injection or exploit)
VBScript performs obfuscated calls to suspicious functions
Windows Scripting host queries suspicious COM object (likely to drop second stage)
WScript reads language and country specific registry keys (likely country aware script)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1901314 Sample: Statement_Viewer.vbs Startdate: 20/04/2026 Architecture: WINDOWS Score: 100 57 pub-f578b8a86388494fb6576071e2515e8b.r2.dev 2->57 65 Multi AV Scanner detection for dropped file 2->65 67 Multi AV Scanner detection for submitted file 2->67 69 .NET source code references suspicious native API functions 2->69 71 6 other signatures 2->71 8 msiexec.exe 94 53 2->8         started        12 wscript.exe 1 2->12         started        14 ScreenConnect.ClientService.exe 2 5 2->14         started        17 4 other processes 2->17 signatures3 process4 dnsIp5 49 C:\Windows\Installer\MSIEDE2.tmp, PE32 8->49 dropped 51 C:\Windows\Installer\MSIE844.tmp, PE32 8->51 dropped 53 C:\Windows\Installer\MSIE41B.tmp, PE32 8->53 dropped 55 11 other files (9 malicious) 8->55 dropped 83 Enables network access during safeboot for specific services 8->83 85 Modifies security policies related information 8->85 19 msiexec.exe 8->19         started        21 msiexec.exe 1 8->21         started        87 VBScript performs obfuscated calls to suspicious functions 12->87 89 Windows Scripting host queries suspicious COM object (likely to drop second stage) 12->89 91 WScript reads language and country specific registry keys (likely country aware script) 12->91 23 wscript.exe 16 12->23         started        61 38.240.59.97, 49694, 8041 COGENT-174US United States 14->61 93 Reads the Security eventlog 14->93 95 Reads the System eventlog 14->95 27 ScreenConnect.WindowsClient.exe 3 14->27         started        29 ScreenConnect.WindowsClient.exe 2 14->29         started        97 Changes security center settings (notifications, updates, antivirus, firewall) 17->97 31 MpCmdRun.exe 1 17->31         started        file6 signatures7 process8 dnsIp9 33 rundll32.exe 11 19->33         started        59 pub-f578b8a86388494fb6576071e2515e8b.r2.dev 104.18.50.34, 443, 49693 CLOUDFLARENETUS United States 23->59 73 System process connects to network (likely due to code injection or exploit) 23->73 75 Windows Scripting host queries suspicious COM object (likely to drop second stage) 23->75 77 WScript reads language and country specific registry keys (likely country aware script) 23->77 37 msiexec.exe 23->37         started        79 Creates files in the system32 config directory 27->79 81 Contains functionality to hide user accounts 27->81 39 conhost.exe 31->39         started        signatures10 process11 file12 41 C:\Windows\...\ScreenConnect.Windows.dll, PE32 33->41 dropped 43 C:\...\ScreenConnect.InstallerActions.dll, PE32 33->43 dropped 45 C:\Windows\...\ScreenConnect.Core.dll, PE32 33->45 dropped 47 4 other malicious files 33->47 dropped 63 Contains functionality to hide user accounts 33->63 signatures13
Gathering data
Verdict:
Malicious
Threat:
RemoteAdmin.MSIL.ConnectWise
Threat name:
Win32.Trojan.Kepavll
Status:
Malicious
First seen:
2026-04-20 15:01:11 UTC
File Type:
Text (VBS)
AV detection:
11 of 38 (28.95%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
admintool_screenconnect
Similar samples:
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:detect_tiny_vbs
Author:daniyyell
Description:Detects tiny VBS delivery technique

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments