🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3b13cbd8ff8b58ac8c3f2ca1471f5da0135f748142b80ab0191bd2a5965e089d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GoToResolve


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 3b13cbd8ff8b58ac8c3f2ca1471f5da0135f748142b80ab0191bd2a5965e089d
SHA3-384 hash: 8224c16a4baea6c64d8fbb40f940ce373854ff4a0b9700b07ee88ae0c8dbae7543b1d25ea6cfd31d358adb2b9a6f1d8e
SHA1 hash: bcf11a154e50edfdfa0180a1773719ea4aa86bb5
MD5 hash: 8bf58b4d459599ac6a5836550137ab7e
humanhash: robin-nine-wolfram-cola
File name:DocuSign_Viewer_v64-Build-637563_Installer.vbs
Download: download sample
Signature GoToResolve
File size:2'115 bytes
First seen:2026-05-17 01:17:41 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 48:XgTYWDW30QbbQijAu9DYIYoRqY2ctDceE4vibO2RYIsq:X1k6/DYI5RqY28A2XwJ
TLSH T1854183EA3C09512089750677AB661BB1E7EA05AF34270018388AC89A1F327BF67C90F4
Magika vba
Reporter Anonymous
Tags:vbs


Avatar
Anonymous
Downloaded from hxxps[://]orderamazxondetailsdownloader[.]info/order_mobile[.]php

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
CZ CZ
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
90.2%
Tags:
dropper virus blic
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive lolbin msiexec
Verdict:
Malicious
File Type:
vbs
First seen:
2026-05-11T09:51:00Z UTC
Last seen:
2026-05-12T02:00:00Z UTC
Hits:
~100
Verdict:
Malware
YARA:
1 match(es)
Tags:
ADODB.Stream Scripting.FileSystemObject Shell.Application VBScript WinHttp.WinHttpRequest.5.1 WScript.Shell
Verdict:
Malicious
Threat:
Trojan-Downloader.VBS.Agent
Threat name:
Win32.Trojan.Qwexlafiba
Status:
Malicious
First seen:
2026-05-11 12:48:43 UTC
File Type:
Text (VBS)
AV detection:
7 of 24 (29.17%)
Threat level:
  5/5
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

GoToResolve

Visual Basic Script (vbs) vbs 3b13cbd8ff8b58ac8c3f2ca1471f5da0135f748142b80ab0191bd2a5965e089d

(this sample)

Comments