🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d26d2cd679fa7c81b19e6a724f414cedc50769c214d9f4d130fcbb2bd3cad5b3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ConnectWise


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: d26d2cd679fa7c81b19e6a724f414cedc50769c214d9f4d130fcbb2bd3cad5b3
SHA3-384 hash: 99722b16862a58068f27f564c3ce8672a7a209d2f1c4ab871579fb0a8c25549899d2b56296b93615aa13ebee3335fd7e
SHA1 hash: f9a92e8b7d5ab9469910a1656273cba6ef3667ab
MD5 hash: 6f361a9777cb7f661ad3c6b4c4112a9e
humanhash: eight-neptune-maine-cat
File name:Event-Manual-sync.zip
Download: download sample
Signature ConnectWise
File size:769 bytes
First seen:2026-10-03 21:13:19 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12:5jJ6IOX/9OkUAnLf3nhcc/iRzwJffbeLSlYIU/ZTrHdGlMXHyGk0ziaX:9JaMgn6qtSlIUR3MlUHkKJ
TLSH T10501BA24C70382F3F15FC2B743513741E0F8154729E5AEDD12189295C9B5359E7F0755
Magika zip
Reporter Anonymous
Tags:screenconnect zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
119
Origin country :
CZ CZ
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Event-Manual.vbs
File size:1'069 bytes
SHA256 hash: 6a514da7cac790d657c1785c71c2d5efdbacadd117e3220f9221c40e245d9508
MD5 hash: 0dd582fd917694c6aa99e09ec1c7019a
MIME type:text/plain
Signature ConnectWise
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
VBS File - Malicious
Payload URLs
URL
File name
https://moneylord.org/Bin/ScreenConnect.ClientSetup.msi?e=Access&y=Guest
VBS File
Behaviour
BlacklistAPI detected
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
downloader evasive expand lolbin lolbin msiexec rundll32 wscript
Verdict:
Malicious
File Type:
zip
First seen:
2026-10-03T19:31:00Z UTC
Last seen:
2026-10-03T19:40:00Z UTC
Hits:
~10
Verdict:
Malware
YARA:
2 match(es)
Tags:
ADODB.Stream COM Behavior Trace DeObfuscated MSXML2.XMLHTTP Obfuscated Shell.Application T1027 T1059.005 T1105 VBScript WScript.Shell Zip Archive
Threat name:
Script-ActiveX.Trojan.Heuristic
Status:
Malicious
First seen:
2026-10-03 21:14:22 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
9 of 24 (37.50%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ConnectWise

zip d26d2cd679fa7c81b19e6a724f414cedc50769c214d9f4d130fcbb2bd3cad5b3

(this sample)

  
Delivery method
Distributed via web download

Comments