🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7a7b8eef418a8dee833097b2f077d783cecc51e1dd66778d52c54268d422f7d0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 7a7b8eef418a8dee833097b2f077d783cecc51e1dd66778d52c54268d422f7d0
SHA3-384 hash: 736acf08dd11decd13136e945be4f73a96a67fcc4090116149c70e0cb1d8e9e53669839c79a049189bfe1cc6888bab7d
SHA1 hash: 9a20b9f04222787abaf95f6131b90ccbc3babd94
MD5 hash: 54f4c9e754136c302009a54e49c39c96
humanhash: six-finch-whiskey-juliet
File name:Document-52848.pdf                                                  .vbs
Download: download sample
File size:2'595 bytes
First seen:2026-09-06 19:44:23 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 48:AyDXYHsggT7pbvxpEqi3jj8ddALhn27YkLpcdAjchnDFXzWdLBYndAlSA6S:AyDXYDg3NvxppiErv448OSc
TLSH T1FF519467AE59CD3CF8631A1382BAEC2E7E6C05137C52C4C7E06D864436A877853DA40B
Magika vba
Reporter ShadowOpCode
Tags:neonstriker99 NeonVanguard vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cscript downloader evasive evasive lolbin masquerade persistence
Verdict:
Malicious
File Type:
vbs
First seen:
2026-09-06T17:49:00Z UTC
Last seen:
2026-09-07T00:48:00Z UTC
Hits:
~1000
Verdict:
Malware
YARA:
1 match(es)
Tags:
Batch Command COM Behavior Trace DeObfuscated Obfuscated PowerShell PowerShell Call Scripting.FileSystemObject SOS: 0.34 T1027 T1059 T1059.001 T1059.005 T1105 VBScript WScript.Shell
Threat name:
Win32.Trojan.Egairtigado
Status:
Malicious
First seen:
2026-09-06 19:45:39 UTC
File Type:
Text (VBS)
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery execution persistence spyware stealer
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Modifies registry key
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
cURL User-Agent
Browser Information Discovery
Enumerates physical storage devices
Executes a command shell one-liner
System Time Discovery
Drops file in Program Files directory
Drops file in Windows directory
Executes a VBScript file via the Windows Script Host.
Adds Run key to start application
Enumerates connected drives
Looks up external IP address via web service
Checks computer location settings
Deletes itself
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments