MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 96986991e6afc47c446c9f789014d6931ddc84d1f52257e77d8da915f985ed39. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ConnectWise


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 96986991e6afc47c446c9f789014d6931ddc84d1f52257e77d8da915f985ed39
SHA3-384 hash: b7be0425c35b4089b510017bec833ea559d6b91d324920a79e1b6bcf254c32314b43cdb86997884dc2bbbabcd137cf1c
SHA1 hash: c78b3a581f7dabadf3766be0b38235cb7dcd3821
MD5 hash: 0600f4f3def44de41f920511d203927f
humanhash: april-autumn-whiskey-two
File name:Zoom_exe.vbs
Download: download sample
Signature ConnectWise
File size:28'423 bytes
First seen:2026-07-23 14:25:22 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 384:TbhpFbNSWPy6vrdobdPSLHBldGpZtAY8pM5XxpheNK0vXc/PduhUOHSE5:T/FbNnPzSRZ5N4vc/Fuh1t5
TLSH T102D224D953469AE0FD5C1E0EDAA5440220F3D6ACFA261189CE3159E33E33E85447DEBE
Magika vba
Reporter Anonymous
Tags:ConnectWise vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
121
Origin country :
GR GR
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm encrypted evasive evasive expand fingerprint lolbin msiexec obfuscated persistence powershell rundll32 schtasks timeout timeout wscript
Verdict:
Malicious
File Type:
vbs
First seen:
2026-07-23T12:17:00Z UTC
Last seen:
2026-07-23T14:31:00Z UTC
Hits:
~10
Gathering data
Threat name:
Text.Trojan.Rempi
Status:
Malicious
First seen:
2026-07-23 14:25:44 UTC
File Type:
Text (VBA)
AV detection:
4 of 36 (11.11%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  9/10
Tags:
backdoor defense_evasion discovery execution persistence privilege_escalation ransomware rat revoked_codesign
Behaviour
Checks processor information in registry
Delays execution with timeout.exe
Modifies data under HKEY_USERS
Modifies registry class
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Enumerates physical storage devices
Executes a command shell one-liner
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Drops file in Windows directory
Boot or Logon Autostart Execution: Authentication Package
Drops file in System32 directory
Executes a VBScript file via the Windows Script Host.
Adds Run key to start application
Enumerates connected drives
Indicator Removal: File Deletion
Checks computer location settings
ConnectWise ScreenConnect remote access tool
Event Triggered Execution: Component Object Model Hijacking
Executes dropped EXE
Loads dropped DLL
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Sets service image path in registry
Signed with revoked ConnectWise certificate
Clears Windows event logs
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments