🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 03c829f0fdfcc02d3ad8517d2476ca95f57c85b32797d4187c2ac3db5c65cdba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 03c829f0fdfcc02d3ad8517d2476ca95f57c85b32797d4187c2ac3db5c65cdba
SHA3-384 hash: 4301deb55e9992ab660146fb2de2bc2415808f0a0390e56e9e8e67eace6eb3ea64a93566a528968a89bcdcbed4f1827c
SHA1 hash: 494a7b02e96cb26df43ab3372b1fdc87c7ae2cd6
MD5 hash: f00532ac13903662edb4d6a4c4dacf04
humanhash: zebra-seventeen-seventeen-ack
File name:fulcra.vbs
Download: download sample
File size:3'788 bytes
First seen:2026-05-20 23:38:38 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:application/octet-stream
ssdeep 48:50OP70vwHaPlO0PSCBWCL3lPTZGVPrXXsx12BaaLxRIuXoexqssa6x4aNyiixSXl:bknXr
TLSH T1F0711A65E88A31C9EB5D26B6BBC072E704961663B63D63019165C0332BBC1BFD3306F5
Magika vba
Reporter BastianHein
Tags:vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
23
Origin country :
CL CL
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
92.5%
Tags:
downloader hype
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
obfuscated
Verdict:
Malicious
File Type:
text.utf8
First seen:
2026-05-20T23:12:00Z UTC
Last seen:
2026-05-21T07:50:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan.Script.Generic
Gathering data
Gathering data
Threat name:
Script.Downloader.DarkCloud
Status:
Malicious
First seen:
2026-05-21 04:52:47 UTC
File Type:
Binary
AV detection:
15 of 38 (39.47%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments