🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e50f4e17242dd0e25b83cc30e9be43bcbbfcf7ad4c3caf28d6ce11e1ba374815. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: e50f4e17242dd0e25b83cc30e9be43bcbbfcf7ad4c3caf28d6ce11e1ba374815
SHA3-384 hash: 4b3e461c05bfaac6e0113b724fa0163b0ff3685ebef0a6fa8d7b2316bd36a815edea16cb2fe1a3872a41ab9734043631
SHA1 hash: 42b09425829cbad72884518ce30c2b18a0fcfeb1
MD5 hash: 3617eae37829ab5388df5d8a3bb9e5e9
humanhash: mexico-mirror-vegan-east
File name:pdf.vbs
Download: download sample
File size:12'474 bytes
First seen:2026-10-03 19:03:27 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 192:fCiBIBZEEtTEBfzym4jKjdP/9IY83mP7eVMUrGxE:foEEZZj6iY83mP7eVVyE
TLSH T1A5428B0263FA0608F1F36B58AEB694750B27BE65A97DD24C018C284E4FF3A44D8657F7
TrID 66.6% (.TXT) Text - UTF-16 (LE) encoded (2000/1)
33.3% (.MP3) MP3 audio (1000/1)
Magika vba
Reporter smica83
Tags:vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
base64 obfuscated
Verdict:
Malicious
File Type:
vbs
First seen:
2026-10-03T05:26:00Z UTC
Last seen:
2026-10-03T06:03:00Z UTC
Hits:
~100
Result
Threat name:
n/a
Detection:
malicious
Classification:
spre.troj.expl.evad
Score:
100 / 100
Signature
AI detected malicious Powershell script
Benign windows process drops PE files
Creates an undocumented autostart registry key
Found direct / indirect Syscall (likely to bypass EDR)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Hides threads from debuggers
Multi AV Scanner detection for submitted file
Performs DNS queries to domains with low reputation
Potential Privilege Escalation using Task Scheduler highest RunLevel
Sigma detected: Script Initiated Connection to Non-Local Network
Sigma detected: WScript or CScript Dropper
System process connects to network (likely due to code injection or exploit)
Unusual module load detection (module proxying)
Uses schtasks.exe or at.exe to add and modify task schedules
VBScript performs obfuscated calls to suspicious functions
Windows Scripting host queries suspicious COM object (likely to drop second stage)
WScript reads language and country specific registry keys (likely country aware script)
Yara detected VBS Downloader Generic
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1981765 Sample: pdf.vbs Startdate: 03/10/2026 Architecture: WINDOWS Score: 100 93 authgatemeforever.xyz 2->93 95 release-assets.githubusercontent.com 2->95 97 github.com 2->97 105 Multi AV Scanner detection for submitted file 2->105 107 Yara detected VBS Downloader Generic 2->107 109 Sigma detected: WScript or CScript Dropper 2->109 113 2 other signatures 2->113 12 wscript.exe 1 7 2->12         started        17 MicrosoftEdgeUpdate.exe 2->17         started        19 OfficeClickToRunSvc.exe 2->19         started        signatures3 111 Performs DNS queries to domains with low reputation 93->111 process4 dnsIp5 101 release-assets.githubusercontent.com 185.199.111.133, 443, 49710 FASTLY-FastlyIncUS United States 12->101 103 github.com 172.182.252.133, 443, 49709 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS United States 12->103 87 C:\...\mkx5uiuqdMdCyGdYnUZwYtmuYQUCaqtV.exe, PE32+ 12->87 dropped 89 C:\Users\user\AppData\...\vcruntime140.dll, PE32+ 12->89 dropped 91 C:\Users\user\AppData\Local\...\WWLIB.dll, PE32+ 12->91 dropped 141 System process connects to network (likely due to code injection or exploit) 12->141 143 Benign windows process drops PE files 12->143 145 VBScript performs obfuscated calls to suspicious functions 12->145 151 2 other signatures 12->151 21 mkx5uiuqdMdCyGdYnUZwYtmuYQUCaqtV.exe 1 12->21         started        147 Hides threads from debuggers 17->147 149 Hides that the sample has been downloaded from the Internet (zone.identifier) 17->149 file6 signatures7 process8 signatures9 115 Uses schtasks.exe or at.exe to add and modify task schedules 21->115 117 Potential Privilege Escalation using Task Scheduler highest RunLevel 21->117 119 Unusual module load detection (module proxying) 21->119 24 mkx5uiuqdMdCyGdYnUZwYtmuYQUCaqtV.exe 3 22 21->24         started        process10 dnsIp11 99 authgatemeforever.xyz 176.124.199.25, 443, 49711, 49712 AEZA-ASRU Netherlands 24->99 79 C:\ProgramData\Microsoft\...\vcruntime140.dll, PE32+ 24->79 dropped 81 C:\ProgramData\Microsoft\Office\...\WWLIB.dll, PE32+ 24->81 dropped 83 C:\ProgramData\...\OfficeClickToRunSvc.exe, PE32+ 24->83 dropped 85 3 other malicious files 24->85 dropped 125 Creates an undocumented autostart registry key 24->125 127 Hides threads from debuggers 24->127 129 Hides that the sample has been downloaded from the Internet (zone.identifier) 24->129 131 Found direct / indirect Syscall (likely to bypass EDR) 24->131 29 MicrosoftEdgeUpdate.exe 10 24->29         started        32 MicrosoftEdgeUpdate.exe 10 24->32         started        34 MicrosoftEdgeUpdate.exe 24->34         started        36 6 other processes 24->36 file12 signatures13 process14 signatures15 133 Hides threads from debuggers 29->133 135 Hides that the sample has been downloaded from the Internet (zone.identifier) 29->135 137 Unusual module load detection (module proxying) 29->137 139 Found direct / indirect Syscall (likely to bypass EDR) 29->139 38 MicrosoftEdgeUpdate.exe 29->38         started        41 MicrosoftEdgeUpdate.exe 29->41         started        43 MicrosoftEdgeUpdate.exe 29->43         started        53 2 other processes 29->53 45 schtasks.exe 32->45         started        47 schtasks.exe 32->47         started        49 schtasks.exe 34->49         started        51 schtasks.exe 34->51         started        55 7 other processes 36->55 process16 signatures17 121 Hides threads from debuggers 38->121 123 Hides that the sample has been downloaded from the Internet (zone.identifier) 38->123 57 schtasks.exe 38->57         started        59 schtasks.exe 41->59         started        61 conhost.exe 45->61         started        63 conhost.exe 47->63         started        65 conhost.exe 49->65         started        67 conhost.exe 51->67         started        69 conhost.exe 53->69         started        71 conhost.exe 53->71         started        73 5 other processes 55->73 process18 process19 75 conhost.exe 57->75         started        77 conhost.exe 59->77         started       
Verdict:
Malware
YARA:
1 match(es)
Tags:
ADODB.Stream COM Behavior Trace DeObfuscated Obfuscated Scripting.FileSystemObject Shell.Application SOS: 0.26 T1027 T1047 T1059 T1059.005 T1105 VBScript WinHttp.WinHttpRequest.5.1 WScript.Shell
Result
Malware family:
n/a
Score:
  8/10
Tags:
defense_evasion discovery execution persistence privilege_escalation ransomware spyware stealer
Behaviour
Enumerates system info in registry
Modifies registry class
Scheduled Task/Job: Scheduled Task
Script User-Agent
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Uses Volume Shadow Copy WMI provider
Uses Volume Shadow Copy service COM API
Browser Information Discovery
Direct Volume Access: Opens a physical disk for reading
Enumerates physical storage devices
Reads the TCP/IP host and domain name from the registry
System Time Discovery
Executes a VBScript file via the Windows Script Host.
Suspicious use of NtSetInformationThreadHideFromDebugger
Enumerates connected drives
Checks computer location settings
Event Triggered Execution: Component Object Model Hijacking
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_VBS_Wscript_Shell
Author:SECUINFRA Falcon Team
Description:Detects the definition of 'Wscript.Shell' which is often used by Malware, FPs are possible and commmon

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments