🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2777cfb4d5b747346dabf8df575475511e0a4dc85ec2e14321b340544f44cd19. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 2777cfb4d5b747346dabf8df575475511e0a4dc85ec2e14321b340544f44cd19
SHA3-384 hash: 4041570d7fbef79292e00e43e6436ae43ce5f76ee28feff18ae752fce0252dd7c9b1d996c69bf0b10a506b80d2719643
SHA1 hash: 8d3b70c69249f65c9ef54c708d52c3e2b5b50ff6
MD5 hash: 693d5860e86b6e1bbb8413b3af31cbf6
humanhash: edward-single-pip-happy
File name:r0W0I_tqtgtbfg.vbs
Download: download sample
File size:38'940 bytes
First seen:2026-05-06 19:00:04 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 768:o/qkwH4IDdghPYwSsVAuucivePrlswUCWkou8izo508IWhCeJ7P:f4Iq0srLUxkou8ic5/IWhF
TLSH T1B903499F83480AADF7EC0BC890DA294B06F5D1173C2C164EABB365C3F47B64970756A9
Magika vba
Reporter FXOLabs
Tags:vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
US US
Vendor Threat Intelligence
No detections
Gathering data
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive obfuscated powershell
Verdict:
Malicious
File Type:
vbs
First seen:
2026-05-06T15:36:00Z UTC
Last seen:
2026-05-08T16:50:00Z UTC
Hits:
~100
Detections:
Trojan.JS.SAgent.sb HEUR:Trojan.Script.Generic
Gathering data
Threat name:
Script.Trojan.Heuristic
Status:
Malicious
First seen:
2026-05-06 19:01:01 UTC
File Type:
Text (VBS)
AV detection:
4 of 24 (16.67%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery execution persistence
Behaviour
Checks processor information in registry
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Windows directory
Adds Run key to start application
Enumerates connected drives
Looks up external IP address via web service
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Visual Basic Script (vbs) vbs 2777cfb4d5b747346dabf8df575475511e0a4dc85ec2e14321b340544f44cd19

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments