MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5d004ef1ce214e79cced2e69e1c3ec7e55d58c6b226d3c216629706cfc0f23b2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 5d004ef1ce214e79cced2e69e1c3ec7e55d58c6b226d3c216629706cfc0f23b2
SHA3-384 hash: 54383a862e513560ef181a52561588b3fe0ec5c272918869b08b33ee29c0e5257c4598c7907e10bc0182302b564bea13
SHA1 hash: 477dfc14a560c0ed1c0f984955b4d5f77e3c93ef
MD5 hash: 4785d191a6eac7540d66ca9d1d764d23
humanhash: edward-summer-double-delaware
File name:testx.pdf.vbs
Download: download sample
File size:2'265 bytes
First seen:2026-04-13 17:00:34 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 48:w2KkMAqHP43J0dS5uTgD/A3Nnsk6Afo8/uS:MkUP4ZkS56kUf6qo8mS
TLSH T1BF41B5EFE4169334CE434274016A6D9DDF12E63B15029050FA8C4D45BB109B1F3A13DB
Magika vba
Reporter Mr128BitOff
Tags:refundonex-com stealer-campaign vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
FR FR
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
90.2%
Tags:
virus remo
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
masquerade obfuscated powershell soft-404
Verdict:
Malicious
File Type:
vbs
First seen:
2026-04-13T12:25:00Z UTC
Last seen:
2026-04-14T03:44:00Z UTC
Hits:
~100
Detections:
Trojan.JS.SAgent.sb Trojan-Downloader.Agent.HTTP.C&C HEUR:Trojan-Downloader.Script.Generic
Gathering data
Verdict:
Malicious
Threat:
Trojan-Downloader.Agent.SAgent
Threat name:
Win32.Trojan.Egairtigado
Status:
Malicious
First seen:
2026-04-13 15:40:28 UTC
File Type:
Text (VBS)
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Browser Information Discovery
Enumerates physical storage devices
System Time Discovery
Drops file in Program Files directory
Drops file in Windows directory
Checks computer location settings
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Visual Basic Script (vbs) vbs 5d004ef1ce214e79cced2e69e1c3ec7e55d58c6b226d3c216629706cfc0f23b2

(this sample)

Comments