MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dcc65e18a02dfb9a360694285c0b93faf4e6d8b14af5e4b1c69e261712dfca23. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Guildma


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: dcc65e18a02dfb9a360694285c0b93faf4e6d8b14af5e4b1c69e261712dfca23
SHA3-384 hash: b4bd5a099ba9a5b0b30ffed23102e1d4df8a69301cd4d00d4f4593e8e923d3dea97ca1271b66ad30f354e92ec3b46e4f
SHA1 hash: aa8caa276faa93fd39ec21f229367d9d4a4a2079
MD5 hash: 5765c3adad3bb5eb6f09c9259301df00
humanhash: pizza-potato-monkey-fourteen
File name:4305548766440.vbs
Download: download sample
Signature Guildma
File size:823 bytes
First seen:2026-01-06 13:13:59 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 12:4Y5NtgZp1GhbnmkU5Uotf515uOZCgAbciFaYg6YxXRg/QFVYTYlz7Aw:P5uObnmb5UM515D9AbclyVQFVYG7Aw
TLSH T1C201C4140F78D4B9C39B4C0640BFBE857E81A658062D3375285F690C5284D3EC8778F1
Magika vba
Reporter johnk3r
Tags:banker Downloader guildma vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
obfuscated
Verdict:
Malicious
File Type:
vbs
First seen:
2026-01-06T10:18:00Z UTC
Last seen:
2026-01-07T11:58:00Z UTC
Hits:
~100
Detections:
Trojan.JS.SAgent.sb HEUR:Trojan-Downloader.Script.Generic Trojan-Downloader.Agent.HTTP.C&C PDM:Trojan.Win32.Generic
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
72 / 100
Signature
Multi AV Scanner detection for submitted file
Sigma detected: Script Initiated Connection to Non-Local Network
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
System process connects to network (likely due to code injection or exploit)
Behaviour
Behavior Graph:
Verdict:
Malware
YARA:
1 match(es)
Tags:
VBScript
Threat name:
Script.Trojan.Heuristic
Status:
Malicious
First seen:
2026-01-06 13:14:19 UTC
File Type:
Text (VBS)
AV detection:
5 of 24 (20.83%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments