🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4d40b8a6f816c5f5c43e1d9565e457aaa3bbdb3c974fb2d72ec370f8f515ab36. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 4d40b8a6f816c5f5c43e1d9565e457aaa3bbdb3c974fb2d72ec370f8f515ab36
SHA3-384 hash: 04016f29f2c39f28534d6874ac770a374b346df6b600d13c811fd8b72c8c6cd840a6adc4b182fadae3ea896757a5651c
SHA1 hash: 7ba56d5b99a183d24efadc80b0487b3057df0d14
MD5 hash: dc4d0224e28fc044494cb122e5a1d703
humanhash: sodium-autumn-fanta-blue
File name:Documents.vbs
Download: download sample
File size:26'955 bytes
First seen:2026-05-22 03:28:43 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 384:EozH2H3J46jmkMpmSmEyUP/T44x8CMxWxd7y:NzH2Z46jJwmxUPEE4ATy
TLSH T120C2B1A6B831A163FF7F5A51D99344447DEB0B5A64342CED80798F8C5C039ADD0B88EB
Magika vba
Reporter BastianHein
Tags:vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
95
Origin country :
CL CL
Vendor Threat Intelligence
Malware configuration found for:
GuLoader
Details
GuLoader
a Powershell script
GuLoader
download url(s), a filepath, start offset and size of component in downloaded and Base64 decoded data, and a supplemental deobfuscated downloader script
Verdict:
Malicious
Score:
92.5%
Tags:
obfuscate xtreme sage
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
base64 evasive obfuscated powershell
Verdict:
Malicious
File Type:
vbs
First seen:
2026-05-22T00:36:00Z UTC
Last seen:
2026-05-23T19:00:00Z UTC
Hits:
~10
Detections:
PDM:Trojan.Win32.Generic PDM:Exploit.Win32.Generic Trojan.JS.SAgent.sb HEUR:Trojan.VBS.SAgent.gen HEUR:Trojan.Script.Generic
Gathering data
Threat name:
Script-WScript.Backdoor.FormBook
Status:
Malicious
First seen:
2026-05-22 03:29:34 UTC
File Type:
Text (VBS)
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of SetThreadContext
Command and Scripting Interpreter: PowerShell
Contacts third-party web service commonly abused for C2
Checks computer location settings
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments