Malicious
Malicious

fcf92d3c5637b1a852f27d3a7f037526

VBScript
MD5: fcf92d3c5637b1a852f27d3a7f037526
Size: 1.21 KB
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 fcf92d3c5637b1a852f27d3a7f037526
Sha1 f0dd8239e225fb64668392eb80527a04a7a6562e
Sha256 2c1d5504ad9484383bbfc58fd026f5f1ae8869c95803c4110a77b54ad3adf8a0
Sha384 62949a8d470fae51c8e64f38ae9f3ae5fada96458c3bb36163e0c2a9bc5a807e17699d7b841a7a18a1a426ddcc1db7bf
Sha512 36c52424f61ae392b775f4e113d7a2d38c296d9fec85837f1e37a279baf7595e3566915af7f27ca3d0a38c0466034481ccd216b7ae6ebfc8e916a45c5c85ae30
SSDeep 24:HeGeLuDShawZyoM1j5K3lqaE0K4cp3d5bj2EsB/qaUIeZqaUg+eKZ:+GeSucMsl0TWjaEsgIPgE
TLSH DE2121A9A11EC54D0F97F2C44A7AD038DEB0FA203132D9A8778CC48ED720258671709B
fcf92d3c5637b1a852f27d3a7f037526.deobfuscated.vbs
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1059.005>scr:bat>scr:ps1~T1027~T1059.001
Shape scr:vbs>scr:bat>scr:ps1
malicious 3 nodes
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
[Systehuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
[Systehuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
fcf92d3c5637b1a852f27d3a7f037526.deobfuscated.vbs
Malicious
No malware configuration was found at this point.
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
fcf92d3c5637b1a852f27d3a7f037526
Deobfuscated PowerShell UNKNWOWNmalicious
[Systehuhuhuhuhuhuhuhuhuhuhu
fcf92d3c5637b1a852f27d3a7f037526 › fcf92d3c5637b1a852f27d3a7f037526.deobfuscated.vbs › [Command #1] › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
[Systehuhuhuhuhuhuhuhuhuhuhu
fcf92d3c5637b1a852f27d3a7f037526 › fcf92d3c5637b1a852f27d3a7f037526.deobfuscated.vbs › [Command #0] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙