Malicious
Malicious

fc1c6800c77edd0ba0bc6b195900630d

VBScript
MD5: fc1c6800c77edd0ba0bc6b195900630d
Size: 1.14 MB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 fc1c6800c77edd0ba0bc6b195900630d
Sha1 81ec5cab8148bcef6849be21457808d1bafaa273
Sha256 3d24c75606bfa91bca5fe783134d1b00a2bfb2dbc3da3f14044e172451e0e9b9
Sha384 c211bfdbf9d2218e3771e85d676900ed70b489b734e2264ece9203748bca446392aba86fa2f5d520e6facb08f20889a6
Sha512 d3a25ea85a88739c37239be8bc2046bd641c29ac4ad1f144366f36e98c1c91539d3c4480ab7a98a84527fb0c0eb0be89ba3177d19ec9f287f1ca4a0df51469c4
SSDeep 192:KunDXukimSO7ATOmiCmoow9eeWOFE0q13cqmRVwTbM6+6RUMYTO2+h87jAkmk1eb:Z6371nImE0q1s7RG8Z6RU7zbD1fNK
TLSH 1F3594FF052AE7AAF132FF393CE9E8659E533002115BD0671A16B4BDAA5661270C05FC
fc1c6800c77edd0ba0bc6b195900630d.deobfuscated.vbs
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1059.005>scr:bat~T1027~T1059.001>scr:ps1~T1027~T1059.001
Shape scr:vbs>scr:bat>scr:ps1
malicious 3 nodes
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
Invokehuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
fc1c6800c77edd0ba0bc6b195900630d.deobfuscated.vbs
Malicious
No malware configuration was found at this point.
Deobfuscated PowerShell UNKNWOWNmalicious
powershuhuhuhuhuhuhuhuhuhuhu
fc1c6800c77edd0ba0bc6b195900630d › fc1c6800c77edd0ba0bc6b195900630d.deobfuscated.vbs › [Command #0]
Deobfuscated PowerShell UNKNWOWNmalicious
Invokehuhuhuhuhuhuhuhuhuhuhu
fc1c6800c77edd0ba0bc6b195900630d › fc1c6800c77edd0ba0bc6b195900630d.deobfuscated.vbs › [Command #0] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙