MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 7869ebdc68d79aaa51b73b417d5d6a107ae355761b91f4303c388f4635ff8481. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 5
| SHA256 hash: | 7869ebdc68d79aaa51b73b417d5d6a107ae355761b91f4303c388f4635ff8481 |
|---|---|
| SHA3-384 hash: | 238ce9f1a4c8dee19c45bf6279753abe8a26c99ccc5a09e96bb8a5b8c78b56acfbee9c2cf4f2b91f76a0016007bfe0b6 |
| SHA1 hash: | 498b82eb5334d47950af78246012600872cc9088 |
| MD5 hash: | 9fad588ae21e0cceab91b6debc5a70d2 |
| humanhash: | oven-single-white-alanine |
| File name: | HCGFhPaIrP.vbs |
| Download: | download sample |
| File size: | 109 bytes |
| First seen: | 2026-08-19 20:13:59 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | text/plain |
| ssdeep | 3:YwAuAEFx7D/ecP2RTukVUwg0TKldRHjh6C:YwTAA7yG2Rifwx8Hjhv |
| TLSH | T19BB012119113C3A1F1534FD2D86A83DE91A528C20C5CE3155A91C0DD41BBAB40B453C9 |
| Magika | vba |
| Reporter | |
| Tags: | brazil cryptojacker INDIGO-SHARK Node.js RAT Tor vbs XMRIG |
mensvr
VBS stager/loader, downloads chunked payload from attacker-controlled Blogspot pages, reconstructs and executes the Node.js RAT (chrome.exe), Entry point of the INDIGO-SHARK infection chain.Full analysis: https://mensvr.com/reports/indigo-shark
Intelligence
File Origin
# of uploads :
1
# of downloads :
84
Origin country :
BRVendor Threat Intelligence
No detections
Detection:
n/a
Detection(s):
Verdict:
Suspicious
Threat level:
5/10
Confidence:
100%
Score:
6%
Verdict:
Benign
File Type:
SCRIPT
Verdict:
Malware
YARA:
1 match(es)
Tags:
Scripting.FileSystemObject T1059.005 VBScript
Threat name:
Win32.Trojan.Runner
Status:
Malicious
First seen:
2026-08-19 20:14:40 UTC
File Type:
Text (VBS)
AV detection:
8 of 23 (34.78%)
Threat level:
5/5
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
5/10
Tags:
execution
Behaviour
Executes a VBScript file via the Windows Script Host.
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
vbs 7869ebdc68d79aaa51b73b417d5d6a107ae355761b91f4303c388f4635ff8481
(this sample)
0418692dfc8e114d76eab0ca18e47d68a424a699b24f92f1f69f2e227020df47
Dropping
SHA256 0418692dfc8e114d76eab0ca18e47d68a424a699b24f92f1f69f2e227020df47
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.