MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e22bdb25a2d6a380bd38b3f34b90fcd34563308808c97f807bd8b2ea376cc5dd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: e22bdb25a2d6a380bd38b3f34b90fcd34563308808c97f807bd8b2ea376cc5dd
SHA3-384 hash: 12bc11e1acff44f497ef55597239d3b926946b3674f1e8b0fa647dd3044d891be0db10a4846947928e3e30bcc96a8d71
SHA1 hash: 2899d9e8934c1f9f336481a274c4772732627bff
MD5 hash: 539e8efb812e73c3988329281e94cd96
humanhash: hydrogen-delaware-nuts-red
File name:NFCe-gtin_0f42965a.vbs
Download: download sample
File size:27'878 bytes
First seen:2026-07-16 13:12:03 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 768:sUnwkoIvJg8ib3IXFXX8tAZTYxL5LG4nW9OBlSwaDxdxflhgbJWmZDsIWZiPSrj4:sUnwkoIvJg8ib3IXFXX8tAZTYxL5LG4j
TLSH T1A7C2CA3DCC7C013FC2B7D22DC98E8A07E9925D1B672CED4660D7739A5A13143B89226E
TrID 66.6% (.TXT) Text - UTF-16 (LE) encoded (2000/1)
33.3% (.MP3) MP3 audio (1000/1)
Magika vba
Reporter johnk3r
Tags:trinitycertificadora-fun vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
91
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
90.2%
Tags:
obfuscate extens xtreme
Verdict:
Malicious
File Type:
vbs
First seen:
2026-07-16T11:34:00Z UTC
Last seen:
2026-07-17T19:40:00Z UTC
Hits:
~10
Result
Threat name:
n/a
Detection:
malicious
Classification:
expl.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Found suspicious ZIP file
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Multi AV Scanner detection for submitted file
Powershell drops PE file
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: WScript or CScript Dropper
Sigma detected: WScript or CScript Dropper - File
Suspicious execution chain found
Suspicious powershell command line found
Tries to download and execute files (via powershell)
VBScript performs obfuscated calls to suspicious functions
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Windows Shell Script Host drops VBS files
WScript reads language and country specific registry keys (likely country aware script)
Wscript starts Powershell (via cmd or directly)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1943573 Sample: NFCe-gtin_0f42965a.vbs Startdate: 16/07/2026 Architecture: WINDOWS Score: 100 66 academiablacktrunkss.com 2->66 68 www.python.org 2->68 70 5 other IPs or domains 2->70 88 Antivirus detection for dropped file 2->88 90 Antivirus / Scanner detection for submitted sample 2->90 92 Multi AV Scanner detection for submitted file 2->92 94 6 other signatures 2->94 10 wscript.exe 3 2 2->10         started        14 msiexec.exe 2->14         started        signatures3 process4 file5 64 C:\Users\user\AppData\...\rad478A6.tmp.vbs, ISO-8859 10->64 dropped 100 VBScript performs obfuscated calls to suspicious functions 10->100 102 Suspicious powershell command line found 10->102 104 Wscript starts Powershell (via cmd or directly) 10->104 106 5 other signatures 10->106 16 wscript.exe 2 10->16         started        signatures6 process7 signatures8 80 Suspicious powershell command line found 16->80 82 Wscript starts Powershell (via cmd or directly) 16->82 84 Tries to download and execute files (via powershell) 16->84 86 WScript reads language and country specific registry keys (likely country aware script) 16->86 19 python.exe 1088 16->19         started        23 python.exe 16->23         started        25 powershell.exe 60 16->25         started        28 5 other processes 16->28 process9 dnsIp10 72 151.101.192.223, 443, 49716, 49720 FASTLY-FastlyIncUS Canada 19->72 46 C:\Users\user\PythonPortable\...\pip3.exe, PE32+ 19->46 dropped 48 C:\Users\user\PythonPortable\...\pip3.12.exe, PE32+ 19->48 dropped 56 379 other malicious files 19->56 dropped 30 conhost.exe 19->30         started        58 81 other malicious files 23->58 dropped 32 conhost.exe 23->32         started        50 C:\Users\user\PythonPortable\winsound.pyd, PE32+ 25->50 dropped 52 C:\Users\user\...\vcruntime140_1.dll, PE32+ 25->52 dropped 54 C:\Users\user\...\vcruntime140.dll, PE32+ 25->54 dropped 60 28 other malicious files 25->60 dropped 96 Loading BitLocker PowerShell Module 25->96 34 conhost.exe 25->34         started        74 academiablacktrunkss.com 191.101.131.21, 443, 49722, 49724 TynaHost-DatacenternoBrasilBR Brazil 28->74 76 dualstack.c.ssl.global.fastly.net 151.101.0.175, 443, 49713 FASTLY-FastlyIncUS Canada 28->76 78 pypi.org 151.101.0.223, 443, 49704, 49715 FASTLY-FastlyIncUS Canada 28->78 62 3 other malicious files 28->62 dropped 98 Powershell drops PE file 28->98 36 python.exe 28->36         started        38 conhost.exe 28->38         started        40 conhost.exe 28->40         started        42 3 other processes 28->42 file11 signatures12 process13 process14 44 msiexec.exe 36->44         started       
Verdict:
Malware
YARA:
1 match(es)
Tags:
DeObfuscated Obfuscated Scripting.FileSystemObject T1027 T1059.005 VBScript WScript.Shell
Threat name:
Win32.Dropper.Generic
Status:
Suspicious
First seen:
2026-07-16 13:12:36 UTC
File Type:
Text (VBS)
AV detection:
8 of 24 (33.33%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Command and Scripting Interpreter: PowerShell
Checks computer location settings
Badlisted process makes network request
Malware Config
Dropper Extraction:
https://www.python.org/ftp/python/3.12.3/python-3.12.3-embed-amd64.zip
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments