🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 719675e94befbcc620d8b36afa9523c3d6814b09328c2cae4f6e4657344a252d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 719675e94befbcc620d8b36afa9523c3d6814b09328c2cae4f6e4657344a252d
SHA3-384 hash: b083cb4d20b26bdc55bfd121f394b5e17e16ce438847e9fe405dcc18fb809be924ff041e68f0f73201df626fbfef57cf
SHA1 hash: 265cac8e3262ca0c51012074360b9ab49d2d9784
MD5 hash: 3e57aa151584f6570a6cf6c7bae92132
humanhash: orange-pennsylvania-cold-fish
File name:RFQ#1002190#.vbs
Download: download sample
File size:404'760 bytes
First seen:2026-07-22 08:01:07 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 12288:AJvW3TiDX7F70BRwijX1/az/CEXw3pHOE61s8o:J3wHe
TLSH T1E2844A343DFA501A7173EE558BE878A6EA2FB7633B27585D1091034A4B23941EDC273E
TrID 66.6% (.TXT) Text - UTF-16 (LE) encoded (2000/1)
33.3% (.MP3) MP3 audio (1000/1)
Magika vba
Reporter lowmal3
Tags:vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
85
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
vbs
First seen:
2026-07-12T19:46:00Z UTC
Last seen:
2026-07-24T06:30:00Z UTC
Hits:
~1000
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
76 / 100
Signature
Antivirus / Scanner detection for submitted sample
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for submitted file
Sigma detected: WScript or CScript Dropper
VBScript performs obfuscated calls to suspicious functions
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Behaviour
Behavior Graph:
Verdict:
Malware
YARA:
1 match(es)
Tags:
T1059.005 VBScript
Threat name:
Win32.Trojan.Leonem
Status:
Malicious
First seen:
2026-07-13 00:26:17 UTC
File Type:
Binary
AV detection:
12 of 38 (31.58%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
execution
Behaviour
Executes a VBScript file via the Windows Script Host.
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments