MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 133eaa7631a5e2db1e09dfe8b8303013f6a267b36576136fee9692e84712830d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 133eaa7631a5e2db1e09dfe8b8303013f6a267b36576136fee9692e84712830d
SHA3-384 hash: 5f1b16eb52282540a7ad541cf9f31a7958a5a7e7ad180ff27d9c608fbb71d15a5998510c38d96b05dc174c786d3c9f81
SHA1 hash: 8f9e04e73c5892ac19cfa00cd6020fd06a93888d
MD5 hash: 6638c6b5cc4bf1ae43aea4920d81d0f8
humanhash: helium-minnesota-violet-tango
File name:rbriefing_2658c7fa.vbs
Download: download sample
File size:105'518 bytes
First seen:2026-05-28 06:00:22 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 768:zTMaqWi8PTYUgzRQc30XjFJghTHu5v123xF82zuNTl3HxObN4/ByJ8E6M1o017mu:NBJJo7t03vMSVL4nx
TLSH T185A31541F7F94119BAB72F442AB946B8497BBF92253DC9DDCA100D4E0B32518A93873B
TrID 66.6% (.TXT) Text - UTF-16 (LE) encoded (2000/1)
33.3% (.MP3) MP3 audio (1000/1)
Magika vba
Reporter FXOLabs
Tags:vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
54
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
92.5%
Tags:
obfuscate extens xtreme
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive obfuscated powershell
Verdict:
Malicious
File Type:
vbs
First seen:
2026-05-27T23:24:00Z UTC
Last seen:
2026-05-28T23:20:00Z UTC
Hits:
~100
Detections:
Trojan.JS.SAgent.sb HEUR:Trojan.VBS.SAgent.gen
Gathering data
Result
Malware family:
n/a
Score:
  8/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Visual Basic Script (vbs) vbs 133eaa7631a5e2db1e09dfe8b8303013f6a267b36576136fee9692e84712830d

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments