MALICIOUS — 268b8fdf9834f2c6ad8149b2aa56fad90403c91964ed813609a92b7454ecf34f.vbs
MALICIOUS — 268b8fdf9834f2c6ad8149b2aa56fad90403c91964ed813609a92b7454ecf34f.vbs is a unknown sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (79/100), attributed to the GenericFCA family. 4 of 51 detection engines flagged it.
Identification
- SHA-256:
268b8fdf9834f2c6ad8149b2aa56fad90403c91964ed813609a92b7454ecf34f - SHA-1:
efe58ef1e0e9dc744a701b51a70199b156dfbd12 - MD5:
9b5a4db33036eaaa61bef098f0ef0541 - ssdeep:
6144:Fuptv2hXayOPIW5S0WvNpX52hWD/pLhkRmCKYRTd:i7yOPIWwh1p8SwYYr - TLSH:
T19145FA11344E76A5DBFC9F0E15B6680C2E232BCB6078D5E1F5689AE0D818C20D5CED9B - Submitted as: 268b8fdf9834f2c6ad8149b2aa56fad90403c91964ed813609a92b7454ecf34f.vbs
- File type: unknown · Size: 276322 bytes
- Verdict: malicious (79/100) · Family: GenericFCA
Source: MalwareBazaar · first seen 2026-07-27T00:00:00.000Z · SHA-256 verified
Detections (4 of 51 engines)
- YARA: Trellix/McAfee ATR: ATR_REvil_Sodinokibi
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): Trojan.GenericFCA.9303
- Kaspersky (KVRT): HEUR:Trojan.VBS.SAgent.gen
Why this verdict
The malicious score of 79/100 is the fusion of 3 weighted signals:
- Microsoft Defender flagged flagged (rule
flagged) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.GenericFCA.9303 (rule
Trojan.GenericFCA.9303) - engine signal, weight 0.55, confidence 0.85 - YARA: Trellix/McAfee ATR flagged ATR_REvil_Sodinokibi (rule
ATR_REvil_Sodinokibi) - engine signal, weight 0.35, confidence 0.70
File paths
- C:\Windows\notepad.exe
- C:\windows\SYSTEM32\msiexec.exe
- C:\windows\notepad.exe
More GenericFCA samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report