MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 ed4f7c006b6b3d37e959eba0401908f740b8d2a43fa2c69b0624054c8ae8d22d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 10
| SHA256 hash: | ed4f7c006b6b3d37e959eba0401908f740b8d2a43fa2c69b0624054c8ae8d22d |
|---|---|
| SHA3-384 hash: | 25c8efd02e7fae9bbecffc7f6e54f080c4a6f8947c6da26d0e368d317b0af210ae0b273d84724cb964f5b8be0847dea2 |
| SHA1 hash: | 8123f266d09149baf183a6daf84e910b6a8aede0 |
| MD5 hash: | 54fc3a47c5fad7bbd1d6d7ce84427da1 |
| humanhash: | steak-high-foxtrot-winner |
| File name: | Docsign227.vbs |
| Download: | download sample |
| File size: | 23'874 bytes |
| First seen: | 2026-07-24 12:45:56 UTC |
| Last seen: | 2026-07-24 12:47:28 UTC |
| File type: | |
| MIME type: | text/plain |
| ssdeep | 384:KckSNc/T1TEzprWJhXrAxT7eF2PBX4jUE8fbGO30R/Pr8bTd+I4ov+8O1Ag7A7vb:KOwT0pr+VC6ME872PsdDZ1HrA9i |
| TLSH | T164B2641688058BF3C9EA3555A55BA4D9E510C3A177FB284D3B8EC19C3B7EE108BD10F6 |
| Magika | vba |
| Reporter | |
| Tags: | vbs |
Intelligence
File Origin
# of uploads :
2
# of downloads :
62
Origin country :
CHVendor Threat Intelligence
No detections
Detection:
n/a
Verdict:
Likely Malicious
Threat level:
7.5/10
Confidence:
100%
Tags:
downloader
Verdict:
Malicious
Labled as:
Trojan.Generic
Verdict:
Malicious
File Type:
vbs
First seen:
2026-07-22T05:33:00Z UTC
Last seen:
2026-07-24T08:47:00Z UTC
Hits:
~1000
Score:
99%
Verdict:
Malware
File Type:
SCRIPT
Verdict:
Malware
YARA:
1 match(es)
Tags:
T1059.005 VBScript WScript.Network
Threat name:
Script-PowerShell.Packed.Generic
Status:
Suspicious
First seen:
2026-07-22 11:15:49 UTC
File Type:
Text (VBS)
AV detection:
10 of 36 (27.78%)
Threat level:
1/5
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
8/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Executes a VBScript file via the Windows Script Host.
Command and Scripting Interpreter: PowerShell
Checks computer location settings
Badlisted process makes network request
Malware family:
HomeesNETInjector
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
vbs ed4f7c006b6b3d37e959eba0401908f740b8d2a43fa2c69b0624054c8ae8d22d
(this sample)
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.