MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 1aaa6368a8e5f74c470a8b932e0f6377a752ef52f64b38afa5a30564a52cc5ab. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 5
| SHA256 hash: | 1aaa6368a8e5f74c470a8b932e0f6377a752ef52f64b38afa5a30564a52cc5ab |
|---|---|
| SHA3-384 hash: | 4891caf50889572fb6c5c8b657e4353c4aa0ade6a9f739665fd4f398adbe0a6e637132b59ea3e5c7b906d75a0ec1eda2 |
| SHA1 hash: | a64dd9d2c6c6bde0aef84c6d8c3b95a6f1351cf0 |
| MD5 hash: | da46d047266e1a6a884f38d9868f8afb |
| humanhash: | fourteen-hydrogen-illinois-magnesium |
| File name: | datacustomer6J2124455.vbs |
| Download: | download sample |
| File size: | 32'239 bytes |
| First seen: | 2021-06-01 22:59:09 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | text/plain |
| ssdeep | 768:Inx+p+p0I0uEx13tsteXe6JbQNRL3/VJ/mh8jNMKFLWmheXPjfKrx8:InkpkIVHstRaPurx8 |
| TLSH | D6E219B6EC472D315635A6673C820637EAF150836100A4B0BECE47CD5F7E56901EBAEE |
| Reporter | |
| Tags: | vbs |
Intelligence
File Origin
# of uploads :
1
# of downloads :
137
Origin country :
n/a
Vendor Threat Intelligence
Detection:
n/a
Result
Verdict:
Suspicious
Maliciousness:
Behaviour
Creating a window
Launching a process
Creating a process with a hidden window
Launching cmd.exe command interpreter
Sending a UDP request
Transferring files using the Background Intelligent Transfer Service (BITS)
Connection attempt
Result
Verdict:
UNKNOWN
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
60 / 100
Signature
Multi AV Scanner detection for submitted file
Potential malicious VBS script found (suspicious strings)
VBScript performs obfuscated calls to suspicious functions
Behaviour
Behavior Graph:
Threat name:
Script.Trojan.Bits
Status:
Malicious
First seen:
2021-05-25 08:38:01 UTC
AV detection:
5 of 46 (10.87%)
Threat level:
5/5
Verdict:
unknown
Result
Malware family:
n/a
Score:
1/10
Tags:
n/a
Behaviour
Creates scheduled task(s)
Download via BitsAdmin
Suspicious use of WriteProcessMemory
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
0.90
File information
The table below shows additional information about this malware sample such as delivery method and external references.
vbs 1aaa6368a8e5f74c470a8b932e0f6377a752ef52f64b38afa5a30564a52cc5ab
(this sample)
Delivery method
Distributed via e-mail link
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.