🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a7a1399ebae87153447772eb14439419f9f52d3dcb2bcd5b71ee4057b5e02a7b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Vjw0rm


Vendor detections: 11


Intelligence 11 IOCs 3 YARA 1 File information Comments

SHA256 hash: a7a1399ebae87153447772eb14439419f9f52d3dcb2bcd5b71ee4057b5e02a7b
SHA3-384 hash: 25dcb0c0ec0506f042a6a0cf13c6a2a4df296e803e3a7facfebb68f7ee4e1ed574ea3d6026a230f71cb78c57b14c56b7
SHA1 hash: fda84b46d475dfa149c9318a3a7515ef4ab03d54
MD5 hash: c62baab5d4cfe3de2cfd21e9ee3d166e
humanhash: speaker-kentucky-jig-mirror
File name:ORDER#258400765.XLS.vbs
Download: download sample
Signature Vjw0rm
File size:1'262'788 bytes
First seen:2025-08-04 19:20:07 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 6144:IIJwkw37jX50azBMjWt7LqXZHvHbwMd6arJ3MlNlYBkmQ/Tac:ITygW47WTd6MJ3iPYWmuuc
TLSH T11C453B80BF2CB47089E16E4DB9599CCE11F4E00EAF75255F949CD62B1DB722898DE0E3
Magika vba
Reporter abuse_ch
Tags:vbs vjw0rm


Avatar
abuse_ch
Vjw0rm C2:
206.123.131.164:50161

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
206.123.131.164:50161 https://threatfox.abuse.ch/ioc/1564283/
http://boxyong.ydns.eu:6144/is-ready https://threatfox.abuse.ch/ioc/1564284/
206.123.131.164:6144 https://threatfox.abuse.ch/ioc/1564285/

Intelligence


File Origin
# of uploads :
1
# of downloads :
36
Origin country :
NL NL
Vendor Threat Intelligence
Verdict:
Malicious
Score:
97.4%
Tags:
infosteal asyncrat autorun
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
obfuscated
Result
Threat name:
WSHRat, AsyncRAT, DarkCloud
Detection:
malicious
Classification:
troj.spyw.expl.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
Antivirus detection for dropped file
Benign windows process drops PE files
Bypasses PowerShell execution policy
C2 URLs / IPs found in malware configuration
Creates multiple autostart registry keys
Detected WSHRat
Drops script or batch files to the startup folder
Found malware configuration
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Potential malicious VBS script found (has network functionality)
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Sample uses string decryption to hide its real strings
Sigma detected: Cscript/Wscript Uncommon Script Extension Execution
Sigma detected: Drops script at startup location
Sigma detected: Potentially Suspicious PowerShell Child Processes
Sigma detected: Register Wscript In Run Key
Sigma detected: Script Initiated Connection to Non-Local Network
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: WScript or CScript Dropper
Sigma detected: WScript or CScript Dropper - File
Suricata IDS alerts for network traffic
Suspicious execution chain found
Suspicious powershell command line found
System process connects to network (likely due to code injection or exploit)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal browser information (history, passwords, etc)
Uses an obfuscated file name to hide its real file extension (double extension)
Uses known network protocols on non-standard ports
VBScript performs obfuscated calls to suspicious functions
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript called in batch mode (surpress errors)
Wscript starts Powershell (via cmd or directly)
Yara detected AsyncRAT
Yara detected BrowserPasswordDump
Yara detected Costura Assembly Loader
Yara detected DarkCloud
Yara detected Telegram RAT
Yara detected WSHRAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1750066 Sample: ORDER#258400765.XLS.vbs Startdate: 04/08/2025 Architecture: WINDOWS Score: 100 118 uzoymek25.mywire.org 2->118 120 boxyong.ydns.eu 2->120 122 9 other IPs or domains 2->122 140 Sigma detected: Register Wscript In Run Key 2->140 142 Suricata IDS alerts for network traffic 2->142 144 Found malware configuration 2->144 146 26 other signatures 2->146 15 wscript.exe 3 2 2->15         started        19 wscript.exe 2->19         started        21 wscript.exe 2->21         started        23 3 other processes 2->23 signatures3 process4 file5 112 C:\Users\user\AppData\Local\Temp\QAgtQ.js, ASCII 15->112 dropped 130 Benign windows process drops PE files 15->130 132 Detected WSHRat 15->132 134 VBScript performs obfuscated calls to suspicious functions 15->134 138 5 other signatures 15->138 25 wscript.exe 1 3 15->25         started        136 Wscript called in batch mode (surpress errors) 19->136 28 wscript.exe 19->28         started        signatures6 process7 file8 94 C:\Users\user\AppData\Local\Temp\svchos.js, ASCII 25->94 dropped 31 cmd.exe 25->31         started        34 wscript.exe 2 25->34         started        37 wscript.exe 3 3 25->37         started        156 System process connects to network (likely due to code injection or exploit) 28->156 signatures9 process10 file11 176 Suspicious powershell command line found 31->176 178 Wscript starts Powershell (via cmd or directly) 31->178 39 powershell.exe 31->39         started        41 conhost.exe 31->41         started        90 C:\Users\user\AppData\Local\Temp\PRKZu.exe, PE32 34->90 dropped 180 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 34->180 43 PRKZu.exe 1 6 34->43         started        47 wscript.exe 1 3 37->47         started        49 EXCEL.EXE 48 37->49         started        signatures12 process13 dnsIp14 52 wscript.exe 39->52         started        96 C:\Users\user\AppData\...\Windows Update.exe, PE32 43->96 dropped 158 Antivirus detection for dropped file 43->158 160 Creates multiple autostart registry keys 43->160 55 cmd.exe 43->55         started        98 C:\Users\user\AppData\Roaming\adobe.js, ASCII 47->98 dropped 100 C:\Users\user\AppData\Roaming\...\adobe.js, ASCII 47->100 dropped 162 Windows Scripting host queries suspicious COM object (likely to drop second stage) 47->162 164 Wscript called in batch mode (surpress errors) 47->164 57 wscript.exe 47->57         started        116 s-part-0012.t-0009.t-msedge.net 13.107.246.40, 443, 49761, 49764 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 49->116 file15 signatures16 process17 dnsIp18 148 Windows Scripting host queries suspicious COM object (likely to drop second stage) 52->148 60 wscript.exe 52->60         started        150 Suspicious powershell command line found 55->150 152 Wscript starts Powershell (via cmd or directly) 55->152 154 Bypasses PowerShell execution policy 55->154 65 Windows Update.exe 55->65         started        67 conhost.exe 55->67         started        69 timeout.exe 55->69         started        124 boxyong.ydns.eu 206.123.131.164, 49718, 49740, 49741 M247GB United States 57->124 signatures19 process20 dnsIp21 128 104.168.70.164, 49752, 80 AS-COLOCROSSINGUS United States 60->128 106 C:\Users\user\AppData\Local\Temp\UGQYHP.js, ASCII 60->106 dropped 108 C:\Users\user\AppData\Local\...\uk[1].js, ASCII 60->108 dropped 172 System process connects to network (likely due to code injection or exploit) 60->172 174 Windows Scripting host queries suspicious COM object (likely to drop second stage) 60->174 71 wscript.exe 60->71         started        110 C:\Users\user\AppData\Local\Temp\ajfkxv.vbs, ASCII 65->110 dropped file22 signatures23 process24 file25 92 C:\Users\user\AppData\Local\Temp\xratu.exe, PE32 71->92 dropped 74 xratu.exe 71->74         started        process26 dnsIp27 126 showip.net 162.55.60.2, 49754, 80 ACPCA United States 74->126 102 C:\Users\user\AppData\...\chrome.exe (copy), PE32 74->102 dropped 104 C:\Users\user\AppData\...\Project1.exe, PE32 74->104 dropped 166 Antivirus detection for dropped file 74->166 168 Tries to harvest and steal browser information (history, passwords, etc) 74->168 170 Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes) 74->170 79 chrome.exe 74->79         started        82 taskkill.exe 74->82         started        84 GoogleChrome.exe 74->84         started        86 7 other processes 74->86 file28 signatures29 process30 file31 114 C:\Program Filesbehaviorgraphoogle\...behaviorgraphoogleChrome.exe, PE32 79->114 dropped 88 conhost.exe 82->88         started        process32
Verdict:
Malware
YARA:
1 match(es)
Tags:
AdoDb.stream DeObfuscated Microsoft.xmldom Obfuscated SCRipting.filesystemobject T1059.005 VBScript WScript.Shell
Threat name:
Win32.Trojan.Leonem
Status:
Malicious
First seen:
2025-08-04 19:20:42 UTC
File Type:
Text (VBS)
AV detection:
9 of 38 (23.68%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:asyncrat family:wshrat botnet:default aug defense_evasion discovery execution persistence rat spyware stealer trojan
Behaviour
Checks processor information in registry
Delays execution with timeout.exe
Enumerates system info in registry
Kills process with taskkill
Modifies registry class
Scheduled Task/Job: Scheduled Task
Script User-Agent
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Command and Scripting Interpreter: PowerShell
Adds Run key to start application
Checks computer location settings
Drops startup file
Executes dropped EXE
Reads WinSCP keys stored on the system
Reads user/profile data of web browsers
Blocklisted process makes network request
Async RAT payload
AsyncRat
Asyncrat family
WSHRAT
Wshrat family
Malware Config
C2 Extraction:
uzoymek25.mywire.org:7016
uzoymek25.mywire.org:50161
uzoymek.work.gd:7016
uzoymek.work.gd:50161
boxyong.ydns.eu:7016
boxyong.ydns.eu:50161
http://boxyong.ydns.eu:6144
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:detect_tiny_vbs
Author:daniyyell
Description:Detects tiny VBS delivery technique

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments