🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e655829f7c6cbff1e30399812843ef996b1f37f25bd3c290ecfe7b1e01d74e21. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ConnectWise


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: e655829f7c6cbff1e30399812843ef996b1f37f25bd3c290ecfe7b1e01d74e21
SHA3-384 hash: 53294ff5cb886fbe701edf8b06504d2bb50b9d23eda8ec4f4b1664eb05cb1543178d22f051ba542dbba24ce031a5a1ce
SHA1 hash: b0da9c261c57e2d4e9711f2a6642dab3146c929e
MD5 hash: f345ae10e3d0913359c76729bec3b64e
humanhash: virginia-uncle-johnny-solar
File name:TPD_Quotationsheet Graphic & Barcode Layout requirements.hta
Download: download sample
Signature ConnectWise
File size:12'291 bytes
First seen:2026-09-30 15:27:29 UTC
Last seen:Never
File type:HTML Application (hta) hta
MIME type:text/html
ssdeep 192:tVCWn/1Ml5Zn3B1BnxeHqhd9HBxxpDW+MsYykUBcnjGz4Phj8Tk7WnyC:tVCW/1MxnvxLK+xQxnjLXinyC
TLSH T1F1422110DEC72561B01D2E72C6DA592CF42AA2B3BF357E553C8CA2FC4790EC09D79998
Magika html
Reporter abuse_ch
Tags:ConnectWise hta rmm screenconnect

Intelligence


File Origin
# of uploads :
1
# of downloads :
91
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
hta
First seen:
2026-09-30T07:05:00Z UTC
Last seen:
2026-10-01T10:14:00Z UTC
Hits:
~1000
Result
Threat name:
n/a
Detection:
malicious
Classification:
phis.troj
Score:
68 / 100
Signature
Antivirus detection for URL or domain
Disables the Smart Screen filter
Multi AV Scanner detection for submitted file
Sigma detected: Suspicious MSHTA Child Process
Uses dynamic DNS services
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1980142 Sample: TPD_Quotationsheet Graphic ... Startdate: 30/09/2026 Architecture: WINDOWS Score: 68 24 screen1000.duckdns.org 2->24 30 Antivirus detection for URL or domain 2->30 32 Multi AV Scanner detection for submitted file 2->32 34 Sigma detected: Suspicious MSHTA Child Process 2->34 8 mshta.exe 1 2->8         started        signatures3 36 Uses dynamic DNS services 24->36 process4 process5 10 reg.exe 1 1 8->10         started        13 curl.exe 1 8->13         started        16 reg.exe 1 8->16         started        dnsIp6 38 Disables the Smart Screen filter 10->38 18 conhost.exe 10->18         started        26 screen1000.duckdns.org 45.88.91.72, 443, 49722 VIRTUO-12651980CANADAINCCA United States 13->26 28 127.0.0.1 unknown unknown 13->28 20 conhost.exe 13->20         started        22 conhost.exe 16->22         started        signatures7 process8
Verdict:
Malware
YARA:
3 match(es)
Tags:
DeObfuscated Html Obfuscated SOS: 0.32 T1027 T1059.005 VBScript
Threat name:
Script-WScript.Dropper.Heuristic
Status:
Malicious
First seen:
2026-09-30 10:04:16 UTC
File Type:
Text (HTML)
Extracted files:
1
AV detection:
9 of 24 (37.50%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
discovery execution
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Browser Information Discovery
Enumerates physical storage devices
Executes a command shell one-liner
System Location Discovery: System Language Discovery
System Time Discovery
Drops file in Program Files directory
Drops file in Windows directory
Enumerates connected drives
Checks computer location settings
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Malware Config
Dropper Extraction:
https://screen1000.duckdns.org/Bin/ScreenConnect.ClientSetup.msi?e=Access&y=Guest
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments