🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5bbb1e4d714fac5f326d55fff88e1267f537121d64cb4ba488bb3f7a7215021a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ConnectWise


Vendor detections: 12


Intelligence 12 IOCs YARA 2 File information Comments

SHA256 hash: 5bbb1e4d714fac5f326d55fff88e1267f537121d64cb4ba488bb3f7a7215021a
SHA3-384 hash: ed776fd119676f073b06b2497c3a853faa6bb3908dd5205f2f064bd08522323456a5e6e4b759babbf98833c247973144
SHA1 hash: 8a7a69108ef9a3f7b69ce2ea2c6bddbec5c17b87
MD5 hash: d1cec04c549911555079bb0d6f17bde8
humanhash: low-winner-mississippi-arkansas
File name:Payment-WIRE_COPIER.PDF.js
Download: download sample
Signature ConnectWise
File size:15'875 bytes
First seen:2026-04-06 14:34:11 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 384:Xv3h0Rzu0/HHMiR9oWKAib9b0vQqyTKC7mjc4CwF8UozVk0e0:X/h0Rzu0/HHMiR9oWKAib9wvQqyTKom2
Threatray 1'867 similar samples on MalwareBazaar
TLSH T10A628315BEA4B8CA17434BFB672B31D8FDDE2CEB35458846F68CBC48EA58121D885533
Magika javascript
Reporter abuse_ch
Tags:ConnectWise js rmm screenconnect

Intelligence


File Origin
# of uploads :
1
# of downloads :
139
Origin country :
SE SE
Vendor Threat Intelligence
Gathering data
Verdict:
Malicious
Score:
94.9%
Tags:
connectwise phishing
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
encrypted masquerade obfuscated repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-04-03T18:22:00Z UTC
Last seen:
2026-04-08T12:11:00Z UTC
Hits:
~1000
Detections:
Trojan.Win32.Agent.sb Trojan.JS.SAgent.sb HEUR:Trojan.Script.Generic not-a-virus:RemoteAdmin.Win32.ConnectWise.a RemoteAdmin.ConnectWise.HTTP.C&C
Result
Threat name:
ScreenConnect Tool
Detection:
malicious
Classification:
evad.phis.troj.expl
Score:
100 / 100
Signature
.NET source code contains potential unpacker
.NET source code references suspicious native API functions
AI detected malicious Powershell script
Bypasses PowerShell execution policy
Changes security center settings (notifications, updates, antivirus, firewall)
Contains functionality to hide user accounts
Disables the Smart Screen filter
Enables network access during safeboot for specific services
Joe Sandbox ML detected suspicious sample
JScript performs obfuscated calls to suspicious functions
Modifies security policies related information
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Potential obfuscated javascript found
Reads the Security eventlog
Reads the System eventlog
Sample has a suspicious name (potential lure to open the executable)
Sigma detected: Remote Access Tool - ScreenConnect Suspicious Execution
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious Parent Double Extension File Execution
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Uses an obfuscated file name to hide its real file extension (double extension)
Uses cmd line tools excessively to alter registry or file data
Uses known network protocols on non-standard ports
Windows Scripting host queries suspicious COM object (likely to drop second stage)
WScript reads language and country specific registry keys (likely country aware script)
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1894033 Sample: Payment-WIRE_COPIER.PDF.js Startdate: 06/04/2026 Architecture: WINDOWS Score: 100 80 Multi AV Scanner detection for dropped file 2->80 82 Multi AV Scanner detection for submitted file 2->82 84 .NET source code contains potential unpacker 2->84 86 13 other signatures 2->86 8 msiexec.exe 95 51 2->8         started        12 wscript.exe 1 2 2->12         started        14 ScreenConnect.ClientService.exe 2 5 2->14         started        16 6 other processes 2->16 process3 dnsIp4 66 C:\Windows\Installer\MSI867.tmp, PE32 8->66 dropped 68 C:\Windows\Installer\MSI125D.tmp, PE32 8->68 dropped 70 C:\Windows\Installer\MSI101A.tmp, PE32 8->70 dropped 74 10 other files (8 malicious) 8->74 dropped 102 Enables network access during safeboot for specific services 8->102 104 Modifies security policies related information 8->104 19 msiexec.exe 8->19         started        21 msiexec.exe 1 8->21         started        72 C:\Users\user\...\disable-and-install.log, CSV 12->72 dropped 106 JScript performs obfuscated calls to suspicious functions 12->106 108 Windows Scripting host queries suspicious COM object (likely to drop second stage) 12->108 110 Suspicious execution chain found 12->110 112 WScript reads language and country specific registry keys (likely country aware script) 12->112 23 cscript.exe 1 3 12->23         started        114 Reads the Security eventlog 14->114 116 Reads the System eventlog 14->116 27 ScreenConnect.WindowsClient.exe 2 14->27         started        29 ScreenConnect.WindowsClient.exe 14->29         started        76 127.0.0.1 unknown unknown 16->76 118 Changes security center settings (notifications, updates, antivirus, firewall) 16->118 31 MpCmdRun.exe 16->31         started        file5 signatures6 process7 file8 33 rundll32.exe 11 19->33         started        64 C:\Windows\Temp\download.ps1, ASCII 23->64 dropped 92 JScript performs obfuscated calls to suspicious functions 23->92 94 Suspicious powershell command line found 23->94 96 Uses cmd line tools excessively to alter registry or file data 23->96 98 Bypasses PowerShell execution policy 23->98 37 powershell.exe 14 16 23->37         started        40 reg.exe 1 1 23->40         started        42 reg.exe 1 23->42         started        46 2 other processes 23->46 100 Contains functionality to hide user accounts 27->100 44 conhost.exe 31->44         started        signatures9 process10 dnsIp11 54 C:\Windows\...\ScreenConnect.Windows.dll, PE32 33->54 dropped 56 C:\...\ScreenConnect.InstallerActions.dll, PE32 33->56 dropped 58 C:\Windows\...\ScreenConnect.Core.dll, PE32 33->58 dropped 62 4 other malicious files 33->62 dropped 88 Contains functionality to hide user accounts 33->88 78 5.101.82.22, 49725, 8040 PINDC-ASRU Russian Federation 37->78 60 C:\Windows\Temp\Installer_0.msi, Composite 37->60 dropped 48 conhost.exe 37->48         started        90 Disables the Smart Screen filter 40->90 50 conhost.exe 40->50         started        52 conhost.exe 42->52         started        file12 signatures13 process14
Gathering data
Threat name:
Script-JS.Trojan.Sonbokli
Status:
Malicious
First seen:
2026-04-05 01:00:27 UTC
AV detection:
5 of 38 (13.16%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
backdoor discovery execution persistence privilege_escalation rat revoked_codesign
Behaviour
Checks processor information in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Drops file in Windows directory
Boot or Logon Autostart Execution: Authentication Package
Drops file in System32 directory
Enumerates connected drives
Checks computer location settings
ConnectWise ScreenConnect remote access tool
Event Triggered Execution: Component Object Model Hijacking
Executes dropped EXE
Loads dropped DLL
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Sets service image path in registry
Signed with revoked ConnectWise certificate
Malware Config
Dropper Extraction:
http://5.101.82.22:8040/Bin/ScreenConnect.ClientSetup.msi?e=Access&y=Guest&t=massspamming&c=massspamming&c=&c=&c=&c=&c=&c=&c=
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_obfuscated_JS_obfuscatorio
Author:@imp0rtp3
Description:Detect JS obfuscation done by the js obfuscator (often malicious)
Reference:https://obfuscator.io
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments