🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2ab7812ca829f5e19e3fcd0a1b1ffd71d2d5b9f991af08d8013225ef09ae1140. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ConnectWise


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 2ab7812ca829f5e19e3fcd0a1b1ffd71d2d5b9f991af08d8013225ef09ae1140
SHA3-384 hash: 98c9101566f1f91fc669538e414dbfdbd8742fee45ea1d892d3cea2d4badaac07eec65462fbcdfb776630fb21ad8fe38
SHA1 hash: 7774b4c93f48bc59f1c810d2d2591c41c0db25e5
MD5 hash: 5cbcc864374972d428b3f74f3aedb676
humanhash: orange-video-oven-avocado
File name:File.vbs
Download: download sample
Signature ConnectWise
File size:951 bytes
First seen:2026-09-21 21:28:10 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 24:XhUcuwF5URnas9AH5K37tKRz/MzQebr1XbM7b0JYGARt:XeXAZs7tKRMpi7GA/
TLSH T1B911509CAB0AD1322939838361B7DC4ED77248491C61F4AD7C60CC892D625F85F5D5EB
Magika vba
Reporter Anonymous
Tags:ConnectWise screenconnect vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
109
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive expand lolbin rundll32
Verdict:
Malicious
File Type:
vbs
First seen:
2026-09-21T20:43:00Z UTC
Last seen:
2026-09-23T05:48:00Z UTC
Hits:
~100
Verdict:
Malware
YARA:
1 match(es)
Tags:
ADODB.Stream COM Behavior Trace DeObfuscated Obfuscated Scripting.FileSystemObject Shell.Application T1027 T1059 T1059.005 T1105 VBScript WinHttp.WinHttpRequest.5.1 WScript.Shell
Threat name:
Script.Trojan.Heuristic
Status:
Malicious
First seen:
2026-09-21 21:28:21 UTC
File Type:
Text (VBS)
AV detection:
12 of 38 (31.58%)
Threat level:
  2/5
Verdict:
malicious
Label(s):
ADMINTOOL_ScreenConnect
Result
Malware family:
n/a
Score:
  8/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Executes a VBScript file via the Windows Script Host.
Checks computer location settings
Deletes itself
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments