🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bd3248c0c4fac6181ad03f816d1a7d2effbc65e59e8f97d9300c2ea49a8591e1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: bd3248c0c4fac6181ad03f816d1a7d2effbc65e59e8f97d9300c2ea49a8591e1
SHA3-384 hash: c9617fed8307c77677eff831dbfa28817695f66400bd3cc75be130cdc8827497e0e68c1feb5726e3dc6b19965ee80c3b
SHA1 hash: 723bc29883d95f73148c195462df0e57b761b59c
MD5 hash: 58c18b583da8aad4049278e637e97283
humanhash: uniform-friend-nineteen-tango
File name:INV-350882-3067100.vbs
Download: download sample
File size:29'740 bytes
First seen:2026-10-02 12:56:34 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 768:KSo8szFR/lO33sYBiQ7lKBLdfdjnBSK3pef:k8sX/s8s7InjnBSK3pef
TLSH T13FD2641658458BF0291A3D51F55BBFF5AA10037EF736694A288F8E8C3B365108BF1CA7
Magika vba
Reporter threatcat_ch
Tags:vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
90
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
masquerade
Verdict:
Malicious
File Type:
vbs
First seen:
2026-10-02T06:58:00Z UTC
Last seen:
2026-10-03T10:09:00Z UTC
Hits:
~1000
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
Antivirus detection for dropped file
Antivirus detection for URL or domain
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sigma detected: Bypass UAC via Fodhelper.exe
Sigma detected: Dot net compiler compiles file from suspicious location
Sigma detected: Potential PowerShell Command Line Obfuscation
Sigma detected: Rare Remote Thread Creation By Uncommon Source Image
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Suspicious execution chain found
Suspicious powershell command line found
UAC bypass detected (Fodhelper)
VBScript performs obfuscated calls to suspicious functions
Windows Scripting host queries suspicious COM object (likely to drop second stage)
WScript reads language and country specific registry keys (likely country aware script)
Wscript starts Powershell (via cmd or directly)
Yara detected Telegram RAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1981314 Sample: INV-350882-3067100.vbs Startdate: 02/10/2026 Architecture: WINDOWS Score: 100 96 mr-b01.tm-azurefd.net 2->96 98 casoneroutegold-prod-bggfgca0dkaag8a8.b01.azurefd.net 2->98 102 Suricata IDS alerts for network traffic 2->102 104 Malicious sample detected (through community Yara rule) 2->104 106 Antivirus detection for URL or domain 2->106 108 10 other signatures 2->108 10 wscript.exe 1 2->10         started        13 wscript.exe 2->13         started        15 wscript.exe 2->15         started        17 7 other processes 2->17 signatures3 process4 signatures5 112 VBScript performs obfuscated calls to suspicious functions 10->112 114 Wscript starts Powershell (via cmd or directly) 10->114 116 Windows Scripting host queries suspicious COM object (likely to drop second stage) 10->116 118 Suspicious execution chain found 10->118 19 powershell.exe 10->19         started        120 WScript reads language and country specific registry keys (likely country aware script) 13->120 22 powershell.exe 13->22         started        24 powershell.exe 15->24         started        26 powershell.exe 17->26         started        28 powershell.exe 17->28         started        30 powershell.exe 17->30         started        process6 signatures7 110 Suspicious powershell command line found 19->110 32 AppLaunch.exe 2 2 19->32         started        41 4 other processes 19->41 35 AppLaunch.exe 22->35         started        44 2 other processes 22->44 37 AppLaunch.exe 24->37         started        46 2 other processes 24->46 48 3 other processes 26->48 50 2 other processes 28->50 39 conhost.exe 30->39         started        process8 file9 100 UAC bypass detected (Fodhelper) 32->100 60 2 other processes 32->60 62 2 other processes 35->62 64 2 other processes 37->64 84 C:\Users\user\AppData\Local\...\4jt43c1e.dll, PE32 41->84 dropped 86 C:\ProgramData\tjj31.vbs, ASCII 41->86 dropped 52 cmd.exe 1 41->52         started        66 3 other processes 41->66 88 C:\Users\user\AppData\Local\...\sy2fi1cq.dll, PE32 44->88 dropped 54 cvtres.exe 44->54         started        90 C:\Users\user\AppData\Local\...\k4lqewhp.dll, PE32 46->90 dropped 56 cvtres.exe 46->56         started        92 C:\Users\user\AppData\Local\...\ydfxzsp0.dll, PE32 48->92 dropped 68 3 other processes 48->68 94 C:\Users\user\AppData\Local\...\nolej2gh.dll, PE32 50->94 dropped 58 cvtres.exe 50->58         started        signatures10 process11 process12 70 taskkill.exe 1 52->70         started        72 taskkill.exe 1 52->72         started        74 taskkill.exe 1 52->74         started        76 conhost.exe 52->76         started        78 AppLaunch.exe 60->78         started        80 AppLaunch.exe 62->80         started        82 AppLaunch.exe 64->82         started       
Verdict:
Malware
YARA:
1 match(es)
Tags:
COM Behavior Trace DeObfuscated Obfuscated SOS: 0.64 T1027 T1059 T1059.005 VBScript WScript.Network WScript.Shell
Threat name:
Script-WScript.Trojan.GuLoader
Status:
Malicious
First seen:
2026-10-02 10:48:02 UTC
File Type:
Text (VBS)
AV detection:
11 of 36 (30.56%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
collection defense_evasion discovery execution persistence
Behaviour
Kills process with taskkill
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
Enumerates physical storage devices
Executes a command shell one-liner
Executes a VBScript file via the Windows Script Host.
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Adds Run key to start application
Enumerates connected drives
Looks up external IP address via web service
Checks computer location settings
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Visual Basic Script (vbs) vbs bd3248c0c4fac6181ad03f816d1a7d2effbc65e59e8f97d9300c2ea49a8591e1

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments