🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b7fc11f37433b4f1d357e43b5a26802a96f5f043f70289360d60b12d6248e5ea. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: b7fc11f37433b4f1d357e43b5a26802a96f5f043f70289360d60b12d6248e5ea
SHA3-384 hash: 53c403dc7dd7d185658adbdac672208de1734eaca8209ea2f665e3840c754deaab4d126f839d3ffb381daa57ddbc8999
SHA1 hash: 91899ba8f9c55fa161d5c496c3f181f1f74f3617
MD5 hash: 622358469e5e24114dd0eb03da815576
humanhash: papa-mississippi-nevada-steak
File name:s.vbs
Download: download sample
File size:1'604 bytes
First seen:2024-09-16 16:34:44 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 48:UqTuJS4G7ekININOtTW3MmIzuqvhMKfldjnTxhd:1TuJRG7DISNuT5mICqp7djnlhd
TLSH T1FC31EA6943D2330BB4600E8082BDD7908571B897386CC4FED20FD8202A34C19E70F7EA
Magika vba
Reporter JAMESWT_WT
Tags:64-49-14-181 vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
104
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Malicious
Score:
93.3%
Tags:
Execution Stealth
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
persistence powershell
Result
Threat name:
n/a
Detection:
malicious
Classification:
expl.evad
Score:
100 / 100
Signature
AI detected suspicious sample
Bypasses PowerShell execution policy
Creates an autostart registry key pointing to binary in C:\Windows
Creates autostart registry keys with suspicious values (likely registry only malware)
Sigma detected: Register Wscript In Run Key
Sigma detected: Suspicious PowerShell Parameter Substring
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Uses schtasks.exe or at.exe to add and modify task schedules
VBScript performs obfuscated calls to suspicious functions
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript called in batch mode (surpress errors)
Wscript starts Powershell (via cmd or directly)
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1512056 Sample: s.vbs Startdate: 16/09/2024 Architecture: WINDOWS Score: 100 39 Sigma detected: Register Wscript In Run Key 2->39 41 Sigma detected: WScript or CScript Dropper 2->41 43 Sigma detected: Suspicious PowerShell Parameter Substring 2->43 45 2 other signatures 2->45 7 wscript.exe 8 2 2->7         started        10 svchost.exe 1 1 2->10         started        13 wscript.exe 2->13         started        15 4 other processes 2->15 process3 dnsIp4 49 VBScript performs obfuscated calls to suspicious functions 7->49 51 Wscript starts Powershell (via cmd or directly) 7->51 53 Bypasses PowerShell execution policy 7->53 55 2 other signatures 7->55 17 cmd.exe 1 7->17         started        19 cmd.exe 1 7->19         started        22 powershell.exe 15 7->22         started        24 WINWORD.EXE 129 452 7->24         started        37 127.0.0.1 unknown unknown 10->37 signatures5 process6 signatures7 26 reg.exe 1 1 17->26         started        29 conhost.exe 17->29         started        47 Uses schtasks.exe or at.exe to add and modify task schedules 19->47 31 conhost.exe 19->31         started        33 schtasks.exe 1 19->33         started        35 conhost.exe 22->35         started        process8 signatures9 57 Creates autostart registry keys with suspicious values (likely registry only malware) 26->57 59 Creates an autostart registry key pointing to binary in C:\Windows 26->59
Threat name:
Win32.Downloader.Generic
Status:
Suspicious
First seen:
2024-09-16 15:56:30 UTC
File Type:
Text (VBS)
AV detection:
4 of 38 (10.53%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery execution persistence
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies registry class
Scheduled Task/Job: Scheduled Task
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Office loads VBA resources, possible macro or embedded object present
Command and Scripting Interpreter: PowerShell
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Windows directory
Adds Run key to start application
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments