logo

Analysis Of A VBScript Bot

ID: 9312c215-1d52-5ef4-b1e7-0076f40da020

STIX ID: report--9312c215-1d52-5ef4-b1e7-0076f40da020

Feed Name: Zscaler Security Research Blog

Threat Score
65/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**Executive Summary:** Zscaler ThreatLabZ analyzed an encoded VBScript bot distributed via spam that persists by copying itself to startup and temp folders and adding a Run registry entry, then calls back to a C2 over HTTP to receive a wide range of remote commands (execute, update, uninstall, file enumeration, process listing, command shell, send/recv), and the report demonstrates decoding the .vbe, observing callbacks, and exercising commands to illustrate impact while noting Zscaler blocks its communication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.