🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2808fbfdcf7a9ff91b2e3a561acfb32a3b7a0c5eb8f5abd8e1eda2d1434d64eb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 2808fbfdcf7a9ff91b2e3a561acfb32a3b7a0c5eb8f5abd8e1eda2d1434d64eb
SHA3-384 hash: e8bb528e468bdcf1d9959b8ff6fc843d72278c448b3b102e921b621776c72bff55832bafe9fe9ea3d4472dbc86a0a092
SHA1 hash: b2d38236a37c6396e104e22debe6a66c1013974a
MD5 hash: 55a0f0bfe7917c4cd217fc0ed8a39801
humanhash: william-beryllium-crazy-zebra
File name:Trip Itinerary details.vbs
Download: download sample
File size:88'486 bytes
First seen:2026-05-22 16:52:54 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 768:M1TlbFCwhGy3PtGqBpn4hykb9bsBEnE6EH/30ZnfY2Ebt2dUN:MxxFX72LmwnfYLAdUN
TLSH T12D837816F99B8518B2B28A4B6D93F1754BBF384A2D7C844914CC974B4BD3A00C9927FF
TrID 66.6% (.TXT) Text - UTF-16 (LE) encoded (2000/1)
33.3% (.MP3) MP3 audio (1000/1)
Magika vba
Reporter Anonymous
Tags:vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
90
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
90.2%
Tags:
obfuscate xtreme blic
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
base64 obfuscated powershell powershell
Verdict:
Malicious
File Type:
vbs
First seen:
2026-05-22T14:23:00Z UTC
Last seen:
2026-05-23T19:00:00Z UTC
Hits:
~10
Detections:
PDM:Trojan.Win32.Generic Trojan.JS.SAgent.sb HEUR:Trojan.Script.Generic HEUR:Trojan.PowerShell.Generic HEUR:Trojan-Downloader.Script.Generic
Gathering data
Threat name:
Script-WScript.Trojan.Leonem
Status:
Malicious
First seen:
2026-05-21 16:11:26 UTC
File Type:
Text (VBS)
AV detection:
12 of 37 (32.43%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
defense_evasion discovery execution
Behaviour
Runs ping.exe
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Network Configuration Discovery: Internet Connection Discovery
Indicator Removal: File Deletion
.NET Reactor proctector
Checks computer location settings
Drops startup file
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments