MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bfac94bfb53b4c0ac346706b06296353462a26fa3bb09fbfc99e3ca090ec127e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: bfac94bfb53b4c0ac346706b06296353462a26fa3bb09fbfc99e3ca090ec127e
SHA3-384 hash: 537ef97a639960b625c550222182d605f31b16afa4b93481455adadfe3897c3bdc0494450f74e5e9e6998c424cd7c944
SHA1 hash: 3f0a9f219dfacea0494a6ee30acfe509f439b0cf
MD5 hash: ce37c75d35c82f933e14b00f32c25373
humanhash: virginia-maine-bulldog-tennessee
File name:update.vbs
Download: download sample
File size:296 bytes
First seen:2025-04-05 05:47:39 UTC
Last seen:2025-04-06 07:28:29 UTC
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 6:j+q9NqhfgGCXtn+7yQ7ARkKWCOobkyTzFOyPfBY4J:Kqah+g/ARkFCOk/XJ
TLSH T1DBE02B46AD7FDD35DD8E81552637CC2D83B2B7613228F8095B48C7C464791F45716147
Magika vba
Reporter JAMESWT_WT
Tags:api-autodriverfix-online MacOS-Driverfixer vbs

Intelligence


File Origin
# of uploads :
3
# of downloads :
81
Origin country :
IT IT
Vendor Threat Intelligence
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
56 / 100
Signature
Sigma detected: WScript or CScript Dropper
VBScript performs obfuscated calls to suspicious functions
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1657114 Sample: update.vbs Startdate: 05/04/2025 Architecture: WINDOWS Score: 56 17 Sigma detected: WScript or CScript Dropper 2->17 8 wscript.exe 1 2->8         started        process3 signatures4 19 VBScript performs obfuscated calls to suspicious functions 8->19 21 Windows Scripting host queries suspicious COM object (likely to drop second stage) 8->21 11 cmd.exe 1 8->11         started        process5 process6 13 conhost.exe 11->13         started        process7 15 conhost.exe 13->15         started       
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments