MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f47dbb997d68ec1253fe7a17280bbf4b1ec35d369f9e59b2eb53ac6c6e267da7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: f47dbb997d68ec1253fe7a17280bbf4b1ec35d369f9e59b2eb53ac6c6e267da7
SHA3-384 hash: 04e796fbb0b89982da8bc46a1d6fa0017d3ccb3d184a5c224acb20db9e5fedb37a66817f962ccdeca8b556002079e3cd
SHA1 hash: 950a74074c57f12064d0aeee5802a905bde78b70
MD5 hash: 541a1773592cdd04a702c1cb310b8cfe
humanhash: equal-blossom-helium-vegan
File name:724826.vbs
Download: download sample
File size:35'255 bytes
First seen:2026-08-10 16:00:54 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 768:TWzPZt6sux8I27llTr7ApVlJwclDiuRkD9yTBazMoBI6:KFt6SIqnHExqklC9
TLSH T129F29D413F8845C9443CB39A225BA3F9A1424EB7EDA04F4AF27C613D27CEE562133A57
Magika vba
Reporter James_inthe_box
Tags:exe vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
161
Origin country :
US US
Vendor Threat Intelligence
No detections
Gathering data
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
encrypted evasive obfuscated powershell
Verdict:
Malicious
File Type:
vbs
First seen:
2026-08-10T02:35:00Z UTC
Last seen:
2026-08-10T12:58:00Z UTC
Hits:
~1000
Gathering data
Threat name:
Script-WScript.Trojan.Heuristic
Status:
Malicious
First seen:
2026-08-10 06:09:41 UTC
File Type:
Text (VBS)
AV detection:
5 of 36 (13.89%)
Threat level:
  2/5
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook discovery execution persistence rat spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Executes a VBScript file via the Windows Script Host.
Adds Run key to start application
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Family: Formbook
Formbook payload
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:detect_tiny_vbs
Author:daniyyell
Description:Detects tiny VBS delivery technique

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments