s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-a90ba7e8fbd3704de10c6ed9c2eef4ce6fb4eb0b670cf0c2b21ade85912db1d4 high

📛 Threat Title

Unknown: Payment Copy.vbs

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: unknown. Size: 2965131 bytes. Reporter: lowmal3. First seen: 2026-05-15 07:53:48.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain copy.vbs VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/copy.vbs

IOC database

Type
domain
Value
copy.vbs
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat MB-a90ba7e8fbd3704de10c6ed9c2eef4ce6fb4eb0b670cf0c2b21ade85912db1d4

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/copy.vbs

hash_sha256 a90ba7e8fbd3704de10c6ed9c2eef4ce6fb4eb0b670cf0c2b21ade85912db1d4 1 feed

IOC database

Type
hash_sha256
Value
a90ba7e8fbd3704de10c6ed9c2eef4ce6fb4eb0b670cf0c2b21ade85912db1d4
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 67cfa25677d7016971cb85338f7825a4 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/67cfa25677d7016971cb85338f7825a4
1 feed

IOC database

Type
hash_md5
Value
67cfa25677d7016971cb85338f7825a4
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/67cfa25677d7016971cb85338f7825a4

References (1)

Remediations (10)

  • web:access.redhat.com

    Executive summary A vulnerability, known as "Copy Fail", has been identified in the Linux kernel's cryptographic interface. A user with a local account could trigger the flaw to gain root privileges, such as that of a system administrator. This issue has been assigned CVE-2026-31431 and has a severity impact of Important. Configuration settings can be used to further mitigate the impact. Even ...

  • web:any.run

    Online sandbox report for payment copy.vbs , tagged as stegocampaign, susp-powershell, github, fody, purecrypter, purelogs, stealer, exfiltration, verdict: Malicious ...

  • web:department.va.gov

    This chapter establishes the VA's policies and procedures relating to payment integrity activities required by the Payment Integrity Information Act of 2019, Office of Management and Budget (OMB) Circular A-123, Appendix C, Requirements for Payment Integrity Improvement and OMB Circular A-136, Financial Reporting Requirements.

  • web:scloud.work

    When a proactive remediation script fails to work as expected, it's much faster to test it locally than wait for the next sync from Intune. In this post, I'll show you how I troubleshoot Intune remediation scripts directly on a Windows device. This includes script locations, relevant logs, and registry entries that help verify what […]

  • web:support.microsoft.com

    This mitigation is enabled by default. On these systems, the VBS-protected encryption keys are bound to the default-enabled boot session VBS CI policy and will only unseal if the matching CI policy version is being enforced.

  • web:www.elevenforum.com

    This will block vulnerable versions of VBS system files that are not updated from being loaded by the operating system. Note Additional mitigations and mitigation support for all supported versions of Windows 10, version 1507 and earlier Windows versions, and Windows Server 2016 and earlier Windows Server versions are planned for future updates.

  • web:www.joesandbox.com

    Java / VBScript file with very long strings (likely obfuscated code) Shows file infection / information gathering behavior (enumerates multiple directory for files)

  • web:www.neowin.net

    Microsoft has published a detailed guidance post on how to deal with a recently uncovered security vulnerability that can downgrade almost all modern Windows 11/10/Server PCs with VBS.

  • web:www.pcrisk.com

    What is HSBC E-Payment Advice email scam? Scammers behind phishing emails try to trick recipients into sharing personal information with them. Most of them ask for usernames and passwords, social security numbers, credit card details, personal identification numbers (PINs), or other sensitive information. This email is used to extract login credentials for email accounts. HSBC E-Payment Advice ...

  • web:www.tenforums.com

    Rollback of these binaries might allow an attacker to circumvent VBS security features and exfiltrate data that is protected by VBS. This issue is described in CVE-2024-21302 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability. To resolve this issue, we will revoke vulnerable VBS system files that are not updated.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.