🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 16341fb0a44ae5ab10cd093724f075106f656e374faf78aed5c06f23e915aa9b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 16341fb0a44ae5ab10cd093724f075106f656e374faf78aed5c06f23e915aa9b
SHA3-384 hash: 23f03912440f13b29b8801fedb1db23072d2e58c2bc4c9fd6a3fdab838b6f942337c381bd8426d1af4b4daf4347430ac
SHA1 hash: 990bf81b0fdc4319a0648d07b94102003327a4cb
MD5 hash: 963090fccb0cb304e5e7f03a55d517ea
humanhash: crazy-gee-ink-mountain
File name:PO _no1DSQV00013019.vbs
Download: download sample
File size:298'038 bytes
First seen:2026-08-19 13:38:37 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 6144:JQCEvYYnzAX3Rnodeay88kwqBV7BuyGWiMvWyTfBN2rJYp+nR9F:JuPkhodsWBypyTBNUnR9F
TLSH T1E3544B3DB0BDD766ECA0026816A2C741053AD4C010A877747FEF6C9DF3B859966A239F
TrID 66.6% (.TXT) Text - UTF-16 (LE) encoded (2000/1)
33.3% (.MP3) MP3 audio (1000/1)
Magika winregistry
Reporter threatcat_ch
Tags:vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
90
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
22 / 100
Signature
Sigma detected: WScript or CScript Dropper
Behaviour
Behavior Graph:
Verdict:
Malware
YARA:
1 match(es)
Tags:
DeObfuscated Obfuscated T1027 T1059.005 VBScript
Threat name:
Script-WScript.Trojan.Heuristic
Status:
Malicious
First seen:
2026-08-19 14:15:02 UTC
AV detection:
5 of 24 (20.83%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
execution
Behaviour
Executes a VBScript file via the Windows Script Host.
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Visual Basic Script (vbs) vbs 16341fb0a44ae5ab10cd093724f075106f656e374faf78aed5c06f23e915aa9b

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments