MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 89ad58a61c6a774c0b66e5fba4a0e7fb83018ed3c27d7d82b910c19f55b41975. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 89ad58a61c6a774c0b66e5fba4a0e7fb83018ed3c27d7d82b910c19f55b41975
SHA3-384 hash: ca2690c619e427aecba93fd857a135807f6e400b8538677ee3ba1969a58a2e174d2a9ab2264d59a095130491ca016be1
SHA1 hash: 70329b4d3a3d8353011408432d6a6c1993a16c3f
MD5 hash: 71d2ff4525f545124ad088b266f6ebf6
humanhash: nebraska-johnny-november-lion
File name:Doc6754321-36265.pdf.vbs
Download: download sample
File size:2'628 bytes
First seen:2026-07-29 13:26:44 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 48:EwC/DXYy5qbWsj3Rov2AjhUsacAsh0XuWqBR6ATdARwP:EwC/DXYy52BlUIuf
TLSH T1C45187BFAF1CC33009923A6742D58C1DA02B4FABACD19880A15FC41E375577646E6C5F
Magika vba
Reporter abuse_ch
Tags:vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm cscript evasive evasive lolbin masquerade persistence
Verdict:
Malicious
File Type:
vbs
First seen:
2026-07-28T14:25:00Z UTC
Last seen:
2026-07-30T19:37:00Z UTC
Hits:
~1000
Detections:
Trojan.Win32.Agent.sb Trojan.JS.SAgent.sb Trojan-Spy.Win32.Sapphire.sb Trojan-Spy.Win32.Agent.a BSS:Trojan.Win32.Generic HEUR:Trojan.VBS.SAgent.gen Trojan.Win32.Pdfer.sba NetTool.cURLGet.HTTP.C&C
Result
Threat name:
n/a
Detection:
malicious
Classification:
expl.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Creates multiple autostart registry keys
Deletes itself after installation
Multi AV Scanner detection for submitted file
Sigma detected: Curl Download And Execute Combination
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Suspicious execution chain found
Unusual module load detection (module proxying)
Uses an obfuscated file name to hide its real file extension (double extension)
VBScript performs obfuscated calls to suspicious functions
Windows Scripting host queries suspicious COM object (likely to drop second stage)
WScript reads language and country specific registry keys (likely country aware script)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1949542 Sample: Doc6754321-36265.pdf.vbs Startdate: 29/07/2026 Architecture: WINDOWS Score: 100 64 e90b66f5c6c3eeb113cee5588db54127.r2.cloudflarestorage.com 2->64 66 bs-deliver-e817.61d8f0e6ac62c139abd08ba5.workers.dev 2->66 78 Suricata IDS alerts for network traffic 2->78 80 Antivirus detection for URL or domain 2->80 82 Antivirus / Scanner detection for submitted sample 2->82 84 6 other signatures 2->84 9 wscript.exe 3 1 2->9         started        signatures3 process4 signatures5 90 VBScript performs obfuscated calls to suspicious functions 9->90 92 Deletes itself after installation 9->92 94 Windows Scripting host queries suspicious COM object (likely to drop second stage) 9->94 96 2 other signatures 9->96 12 cscript.exe 1 7 9->12         started        15 cmd.exe 1 9->15         started        17 cmd.exe 1 9->17         started        19 Acrobat.exe 17 57 9->19         started        process6 signatures7 98 Creates multiple autostart registry keys 12->98 21 cmd.exe 1 12->21         started        23 SearchApp.exe 1 26 12->23         started        27 cmd.exe 1 12->27         started        29 conhost.exe 12->29         started        31 curl.exe 2 15->31         started        34 conhost.exe 15->34         started        36 curl.exe 2 17->36         started        38 conhost.exe 17->38         started        40 AcroCEF.exe 107 19->40         started        process8 dnsIp9 42 tar.exe 520 21->42         started        45 conhost.exe 21->45         started        70 104.21.55.142 CLOUDFLARENET-CloudflareIncUS Canada 23->70 86 Creates multiple autostart registry keys 23->86 88 Unusual module load detection (module proxying) 23->88 47 curl.exe 2 27->47         started        49 conhost.exe 27->49         started        72 e90b66f5c6c3eeb113cee5588db54127.r2.cloudflarestorage.com 172.64.66.1, 443, 49746, 49752 CLOUDFLARENET-CloudflareIncUS Canada 31->72 74 127.0.0.1 unknown unknown 31->74 62 C:\Users\user\...\Doc6754321-39546.pdf, PDF 31->62 dropped 76 bs-deliver-e817.61d8f0e6ac62c139abd08ba5.workers.dev 172.67.170.47, 443, 49749 CLOUDFLARENET-CloudflareIncUS Canada 36->76 51 AcroCEF.exe 7 40->51         started        file10 signatures11 process12 dnsIp13 54 C:\Users\user\AppData\Local\Temp\...\zip.dll, PE32+ 42->54 dropped 56 C:\Users\user\...\windowsaccessbridge-64.dll, PE32+ 42->56 dropped 58 C:\Users\user\AppData\...\w2k_lsa_auth.dll, PE32+ 42->58 dropped 60 124 other files (none is malicious) 42->60 dropped 68 23.35.28.201 AKAMAI-AS-AkamaiTechnologiesIncUS United States 51->68 file14
Verdict:
Malware
YARA:
1 match(es)
Tags:
Scripting.FileSystemObject T1059.005 VBScript WScript.Shell
Threat name:
Win32.Trojan.Egairtigado
Status:
Malicious
First seen:
2026-07-29 13:27:45 UTC
File Type:
Text (VBS)
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery execution
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
cURL User-Agent
Browser Information Discovery
Enumerates physical storage devices
Executes a command shell one-liner
System Time Discovery
Drops file in Program Files directory
Drops file in Windows directory
Executes a VBScript file via the Windows Script Host.
Checks computer location settings
Deletes itself
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments