MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 81a5042fdb3885e4c108bc2a511bc078fa6073f47c72ffe5258ebac85ccdaee8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 81a5042fdb3885e4c108bc2a511bc078fa6073f47c72ffe5258ebac85ccdaee8
SHA3-384 hash: e935afb97e4385f971acc0ca6e160bee5ab4156916820f1193053808375007258eaed17d3e8bfc1ff9dc6d164f99df63
SHA1 hash: f3571243388076dbf424097f83bfe0ea6d063c72
MD5 hash: a0c4f602db0582019ff690d029f6bc0e
humanhash: mississippi-pasta-arkansas-autumn
File name:JPSL82.vbs
Download: download sample
File size:141 bytes
First seen:2026-05-27 09:11:59 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 3:YYGRXkZ6XgQtWEopvF4/x7D/ecOGAyYdss:5WU9BuJ7yjGApt
TLSH T1D6C02B675F1CC0B4004016C340F7DC0FC57250492510F20048C2C8C651DA2340C1E089
Magika vba
Reporter JAMESWT_WT
Tags:remoto-ddins-click vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
97.4%
Tags:
phishing autoit emotet
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
evasive
Verdict:
Suspicious
Labled as:
HEUR_TrojanDownloader_Script_Generic
Verdict:
Malicious
File Type:
vbs
First seen:
2026-05-26T03:39:00Z UTC
Last seen:
2026-05-27T08:39:00Z UTC
Hits:
~100
Detections:
Trojan.JS.SAgent.sb Trojan-Downloader.JS.SLoad.sb HEUR:Trojan-Downloader.Script.Generic
Gathering data
Verdict:
Malicious
Threat:
Trojan-Downloader.JS.SLoad
Result
Malware family:
n/a
Score:
  8/10
Tags:
adware defense_evasion discovery persistence ransomware spyware
Behaviour
Checks processor information in registry
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Uses Volume Shadow Copy WMI provider
Uses Volume Shadow Copy service COM API
Views/modifies file attributes
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in System32 directory
Suspicious use of SetThreadContext
Adds Run key to start application
Looks up external IP address via web service
Checks computer location settings
Deletes itself
Executes dropped EXE
Loads dropped DLL
Badlisted process makes network request
Downloads MZ/PE file
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments