MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7f3347e8ab745e8a9d4f49ea31fa574225783d3fd0fb89767236cd8e25ec6b5e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA 1 File information Comments

SHA256 hash: 7f3347e8ab745e8a9d4f49ea31fa574225783d3fd0fb89767236cd8e25ec6b5e
SHA3-384 hash: 7b6df917f33ca9197828e0f0c0bf2174b9dbd02d3c941d0d38de327f38e17744fd99f41a99d476857b5424854c1900e5
SHA1 hash: 5adc02ebcc1c9265180d3e447f42eb6a5906f7fa
MD5 hash: 591f0a61ae3446971e98c2d8b7e41d2f
humanhash: uranus-pip-minnesota-xray
File name:Zamowienie zakupu_260600044_20260721.vbs
Download: download sample
File size:1'207'359 bytes
First seen:2026-07-23 12:50:11 UTC
Last seen:2026-07-23 13:24:21 UTC
File type:Visual Basic Script (vbs) vbs
MIME type:text/csv
ssdeep 384:3WjxpXJcrzW8r4cWLWZt74nWlDqq7WnZt74rWFrcpcCnWlIxpXJcrzW5tWerCcD8:hij0kJGFBSuZiOlaOMkOk86LeX
TLSH T1B7459422FAD414F46F517E1302771A44B89C17DBE638246BCA928874D9B78B0D2E7B73
Magika autoit
Reporter James_inthe_box
Tags:exe vbs

Intelligence


File Origin
# of uploads :
2
# of downloads :
172
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
vbs
First seen:
2026-07-21T22:29:00Z UTC
Last seen:
2026-07-23T09:36:00Z UTC
Hits:
~1000
Verdict:
Malware
YARA:
2 match(es)
Tags:
Base64 Block Batch Command Contains Base64 Block DeObfuscated Obfuscated PowerShell PowerShell Call Powershell: Hidden Execution Scripting.FileSystemObject T1027 T1059.001 T1059.005 VBScript WScript.Shell Wscript.Shell
Threat name:
Script-WScript.Backdoor.FormBook
Status:
Malicious
First seen:
2026-07-22 04:29:06 UTC
File Type:
Text (VBS)
AV detection:
8 of 36 (22.22%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Executes a VBScript file via the Windows Script Host.
Checks computer location settings
Drops startup file
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Process spawned unexpected child process
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:detect_tiny_vbs
Author:daniyyell
Description:Detects tiny VBS delivery technique

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments