🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8c78a55c8bf545e0d21b8757eaa0b709b4af47b13d34a38df81045e67026bd96. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: 8c78a55c8bf545e0d21b8757eaa0b709b4af47b13d34a38df81045e67026bd96
SHA3-384 hash: 1674cd4b8554606ae6a24eb42267c80abc1d49635b20860cb1f6504fb27e848fd7455e5539b1fd0068972b10ff32d59e
SHA1 hash: 7987951e8c903cddc30dce00a1726e8e74c8b550
MD5 hash: dc4096d29c2e1ac9c95f739693069730
humanhash: summer-victor-skylark-early
File name:sostener2.vbs
Download: download sample
File size:3'357'503 bytes
First seen:2026-08-09 23:06:15 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/html
ssdeep 49152:8hbooCGOkPYmzEGsBqbhf0gvUvVkjO2zI9iq:V
TLSH T107F512849D788AFB8E1AA86A78F26F1D376C7ED18CC8345A2E1425D3C171A00FD5F56C
Magika vba
Reporter skocherhan
Tags:asegurar2026-duckdns-org vbs


Avatar
skocherhan
http://asegurar2026.duckdns.org/sostener2.vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
23
Origin country :
GB GB
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
dropper
Verdict:
Malicious
File Type:
vbs
First seen:
2026-08-06T18:21:00Z UTC
Last seen:
2026-08-11T03:40:00Z UTC
Hits:
~100
Gathering data
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

d2b9e0853b974a13c6a4f93a86a444f34e8126ff88ba6284c15fe24c597343ba

Visual Basic Script (vbs) vbs 8c78a55c8bf545e0d21b8757eaa0b709b4af47b13d34a38df81045e67026bd96

(this sample)

a75ef31c9a5778f636cffccb7f065b1a

  
Dropped by
SHA256 d2b9e0853b974a13c6a4f93a86a444f34e8126ff88ba6284c15fe24c597343ba
  
Dropping
MD5 a75ef31c9a5778f636cffccb7f065b1a

Comments