MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6b05c845dd0bb6935cf5677036e25674d44a66b9fda129cd6d3ceee9e78eb15f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



VIPKeylogger


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: 6b05c845dd0bb6935cf5677036e25674d44a66b9fda129cd6d3ceee9e78eb15f
SHA3-384 hash: 598e300c53d84782c79f5020ed806ef4cad86a18dbeb82fbe550b587e802c03d4364ac05d40ab02964f89d2e0cf7ac21
SHA1 hash: c6658391deb975bedc021082d8d921bbb5cd7917
MD5 hash: 8ee5bd418515c50d36268b77ae22db25
humanhash: bacon-fix-wolfram-speaker
File name:Biên lai Viettel Post_.js
Download: download sample
Signature VIPKeylogger
File size:1'994'192 bytes
First seen:2026-08-21 08:46:15 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 24576:0cniOOQ0RvH5hgwFVF6yj84xCYKgLlO4J2SkA0gtpuYTrL7iFYXZ0tbctELQCDBU:SZPAE
TLSH T17C95D08877D6262E6B1968F4015EA74124C224C37669D094EEDDCBC2373D213DE3AFAD
Magika javascript
Reporter abuse_ch
Tags:js VIPKeylogger

Intelligence


File Origin
# of uploads :
1
# of downloads :
152
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
encrypted obfuscated repaired
Result
Threat name:
Clipboard Hijacker, Discord Token Steale
Detection:
malicious
Classification:
evad.troj.spyw.expl
Score:
100 / 100
Signature
.NET source code contains process injector
.NET source code references suspicious native API functions
AI detected malicious Powershell script
Antivirus detection for dropped file
Bypasses PowerShell execution policy
C2 URLs / IPs found in malware configuration
Creates a thread in another existing process (thread injection)
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Injects a PE file into a foreign processes
Installs a global keyboard hook
JScript performs obfuscated calls to suspicious functions
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Potential evasive JS / VBS script found (domain check)
Sample uses string decryption to hide its real strings
Sigma detected: Dot net compiler compiles file from suspicious location
Sigma detected: Rare Remote Thread Creation By Uncommon Source Image
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Silenttrinity Stager Msbuild Activity
Sigma detected: Suspicious PowerShell Parameter Substring
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: WScript or CScript Dropper
Sigma detected: WScript or CScript Dropper - File
Suricata IDS alerts for network traffic
Suspicious execution chain found
Suspicious powershell command line found
Tries to detect the country of the analysis system (by using the IP)
Tries to harvest and steal browser information (history, passwords, etc)
Uses the Telegram API (likely for C&C communication)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Windows Shell Script Host drops VBS files
Writes to foreign memory regions
Wscript called in batch mode (surpress errors)
WScript reads language and country specific registry keys (likely country aware script)
Wscript starts Powershell (via cmd or directly)
Yara detected Clipboard Hijacker
Yara detected Discord Token Stealer
Yara detected LxBase RAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1961664 Sample: Bi#U00ean lai Viettel Post_.js Startdate: 21/08/2026 Architecture: WINDOWS Score: 100 76 reallyfreegeoip.org 2->76 78 api.telegram.org 2->78 80 13 other IPs or domains 2->80 106 Suricata IDS alerts for network traffic 2->106 108 Found malware configuration 2->108 110 Antivirus detection for dropped file 2->110 116 19 other signatures 2->116 11 wscript.exe 1 7 2->11         started        15 wscript.exe 1 2->15         started        signatures3 112 Tries to detect the country of the analysis system (by using the IP) 76->112 114 Uses the Telegram API (likely for C&C communication) 78->114 process4 file5 68 C:\Users\user\AppData\...\net_86412_5750.ps1, ASCII 11->68 dropped 70 C:\Users\user\AppData\...\PhotoStudio.vbs, ASCII 11->70 dropped 72 C:\Users\user\AppData\...\PhotoStudio.js, ASCII 11->72 dropped 130 JScript performs obfuscated calls to suspicious functions 11->130 132 Suspicious powershell command line found 11->132 134 Wscript starts Powershell (via cmd or directly) 11->134 138 5 other signatures 11->138 17 powershell.exe 21 11->17         started        136 WScript reads language and country specific registry keys (likely country aware script) 15->136 21 wscript.exe 15->21         started        signatures6 process7 file8 56 C:\Users\user\AppData\...\ztlkeucc.cmdline, Unicode 17->56 dropped 98 Found many strings related to Crypto-Wallets (likely being stolen) 17->98 100 Writes to foreign memory regions 17->100 102 Modifies the context of a thread in another process (thread injection) 17->102 104 Injects a PE file into a foreign processes 17->104 23 MSBuild.exe 17 30 17->23         started        28 conhost.exe 17->28         started        30 csc.exe 3 17->30         started        signatures9 process10 dnsIp11 82 64.89.160.127, 4561, 49757 GHOSTYNETWORKSUS Luxembourg 23->82 84 ip-api.com 208.95.112.1, 49758, 80 TUT-AS-TotalUptimeTechnologiesLLCUS United States 23->84 58 C:\Users\user\AppData\...\.wdf_618cb217.dat, PE32 23->58 dropped 60 C:\Users\user\...\.msdata_f3cb3fda.cache, PE32 23->60 dropped 62 C:\Users\user\AppData\Local\...\msasn1.dll, PE32+ 23->62 dropped 64 C:\Users\user\AppData\Local\Temp\SNAK.js, ASCII 23->64 dropped 120 Found many strings related to Crypto-Wallets (likely being stolen) 23->120 122 Tries to harvest and steal browser information (history, passwords, etc) 23->122 124 Writes to foreign memory regions 23->124 126 Creates a thread in another existing process (thread injection) 23->126 32 wscript.exe 23->32         started        35 chrome.exe 23->35         started        37 WMIC.exe 23->37         started        41 30 other processes 23->41 128 Installs a global keyboard hook 28->128 66 C:\Users\user\AppData\Local\...\ztlkeucc.dll, PE32 30->66 dropped 39 cvtres.exe 1 30->39         started        file12 signatures13 process14 signatures15 92 Suspicious powershell command line found 32->92 94 Wscript starts Powershell (via cmd or directly) 32->94 96 WScript reads language and country specific registry keys (likely country aware script) 32->96 43 powershell.exe 32->43         started        45 chrome.exe 35->45         started        49 conhost.exe 37->49         started        51 WerFault.exe 41->51         started        process16 dnsIp17 53 conhost.exe 43->53         started        86 ogads-pa.clients6.google.com 142.250.101.95, 443, 49787, 49791 GOOGLE-GoogleLLCUS United States 45->86 88 www.google.com 142.251.154.119, 443, 49765, 49766 GOOGLE-GoogleLLCUS United States 45->88 90 2 other IPs or domains 45->90 74 Chrome Cache Entry: 414, PDP-11 45->74 dropped file18 process19 signatures20 118 Installs a global keyboard hook 53->118
Gathering data
Threat name:
Script-JS.Trojan.Heuristic
Status:
Malicious
First seen:
2026-08-21 08:47:23 UTC
File Type:
Text (JavaScript)
AV detection:
5 of 24 (20.83%)
Threat level:
  2/5
Result
Malware family:
vipkeylogger
Score:
  10/10
Tags:
family:lxbaserat family:vipkeylogger botnet:group1 campaign:50a1c5dba7bf421b87dffb824ee0b307 discovery execution keylogger persistence rat stealer
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Browser Information Discovery
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
System Time Discovery
Suspicious use of SetThreadContext
Looks up external IP address via web service
Checks computer location settings
Loads dropped DLL
Command and Scripting Interpreter: PowerShell
Family: LxBaseRAT
Family: VIPKeylogger
Malware Config
C2 Extraction:
64.89.160.127:4561
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments