🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 90f26471abba91edfa4b501c11bfeedb1a2eee79e6361dc730f8944f0c3dd52f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: 90f26471abba91edfa4b501c11bfeedb1a2eee79e6361dc730f8944f0c3dd52f
SHA3-384 hash: 890780b6bdbcfd562f7eb473428357c496c9d63c6bd3200c8763d7e9134256d941afdfa2824d4c1b0530dfa31db29596
SHA1 hash: 67d2b099260c6f2a4860d0c29daa0c1babd123b6
MD5 hash: a28ee8265f46b3baebc6ee76e6b683a3
humanhash: bravo-iowa-oven-table
File name:Booking-Batch-C-17819.vbs
Download: download sample
File size:29'763 bytes
First seen:2026-10-06 07:57:27 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 384:KLkY0UchCa18fpsWK75ORqZ8RaIoHW17Lz6/wcXTA8bI7pzFRYSsZLLx3OIpIuqD:K0vDlxFWpLriT4DWwc2O+2dcSEL
TLSH T1DFD243D688058BF01A263B56B55F741AD91003B57C39794E3A8BD18D3F7AE10CBD34AB
Magika vba
Reporter abuse_ch
Tags:vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
52
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
vbs
First seen:
2026-10-05T07:56:00Z UTC
Last seen:
2026-10-06T21:35:00Z UTC
Hits:
~100
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
Antivirus detection for dropped file
Antivirus detection for URL or domain
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sigma detected: Bypass UAC via Fodhelper.exe
Sigma detected: Dot net compiler compiles file from suspicious location
Sigma detected: Potential PowerShell Command Line Obfuscation
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Suspicious execution chain found
Suspicious powershell command line found
UAC bypass detected (Fodhelper)
VBScript performs obfuscated calls to suspicious functions
Windows Scripting host queries suspicious COM object (likely to drop second stage)
WScript reads language and country specific registry keys (likely country aware script)
Wscript starts Powershell (via cmd or directly)
Yara detected Telegram RAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1982819 Sample: Booking-Batch-C-17819.vbs Startdate: 06/10/2026 Architecture: WINDOWS Score: 100 104 pki-goog.l.google.com 2->104 106 mr-b01.tm-azurefd.net 2->106 108 2 other IPs or domains 2->108 112 Suricata IDS alerts for network traffic 2->112 114 Malicious sample detected (through community Yara rule) 2->114 116 Antivirus detection for URL or domain 2->116 118 9 other signatures 2->118 10 wscript.exe 1 2->10         started        13 wscript.exe 2->13         started        15 wscript.exe 2->15         started        17 7 other processes 2->17 signatures3 process4 signatures5 122 VBScript performs obfuscated calls to suspicious functions 10->122 124 Wscript starts Powershell (via cmd or directly) 10->124 126 Windows Scripting host queries suspicious COM object (likely to drop second stage) 10->126 128 Suspicious execution chain found 10->128 19 powershell.exe 10->19         started        130 WScript reads language and country specific registry keys (likely country aware script) 13->130 22 powershell.exe 13->22         started        24 powershell.exe 15->24         started        26 powershell.exe 17->26         started        28 powershell.exe 17->28         started        30 powershell.exe 17->30         started        32 powershell.exe 17->32         started        process6 signatures7 120 Suspicious powershell command line found 19->120 34 AppLaunch.exe 19->34         started        41 4 other processes 19->41 44 6 other processes 22->44 37 AppLaunch.exe 24->37         started        46 3 other processes 24->46 48 3 other processes 26->48 50 4 other processes 28->50 52 2 other processes 30->52 39 conhost.exe 32->39         started        process8 file9 110 UAC bypass detected (Fodhelper) 34->110 58 2 other processes 34->58 60 2 other processes 37->60 90 C:\Users\user\AppData\Local\...\lrcyy3rp.dll, PE32 41->90 dropped 92 C:\ProgramData\amm.vbs, ASCII 41->92 dropped 54 cmd.exe 1 41->54         started        62 3 other processes 41->62 94 C:\Users\user\AppData\Local\...\pfun210w.dll, PE32 44->94 dropped 64 7 other processes 44->64 96 C:\Users\user\AppData\Local\...\or5fvqtr.dll, PE32 46->96 dropped 66 3 other processes 46->66 98 C:\Users\user\AppData\Local\...\ofst3q1i.dll, PE32 48->98 dropped 68 3 other processes 48->68 100 C:\Users\user\AppData\Local\...\bq4yufrw.dll, PE32 50->100 dropped 70 2 other processes 50->70 102 C:\Users\user\AppData\Local\...\3jegevg5.dll, PE32 52->102 dropped 56 cvtres.exe 52->56         started        signatures10 process11 process12 72 taskkill.exe 1 54->72         started        74 taskkill.exe 1 54->74         started        76 taskkill.exe 1 54->76         started        78 conhost.exe 54->78         started        80 AppLaunch.exe 58->80         started        82 AppLaunch.exe 60->82         started        86 5 other processes 64->86 88 4 other processes 66->88 84 AppLaunch.exe 68->84         started       
Verdict:
Malware
YARA:
1 match(es)
Tags:
COM Behavior Trace DeObfuscated Obfuscated SOS: 0.63 T1027 T1059 T1059.005 VBScript WScript.Network WScript.Shell
Threat name:
Script-WScript.Trojan.GuLoader
Status:
Malicious
First seen:
2026-10-05 12:46:30 UTC
File Type:
Text (VBS)
AV detection:
14 of 36 (38.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
collection defense_evasion discovery execution persistence
Behaviour
Kills process with taskkill
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
Enumerates physical storage devices
Executes a command shell one-liner
Executes a VBScript file via the Windows Script Host.
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Adds Run key to start application
Enumerates connected drives
Looks up external IP address via web service
Checks computer location settings
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MULTI_Malware_GuLoader_ForgeAuto_2fbadefd
Author:Marjoriefort
Description:Detects GuLoader (inconnu, etat binaire)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments