SUSPICIOUS — site.js
SUSPICIOUS — site.js is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 0 of 53 detection engines flagged it.
Identification
- SHA-256:
0accb27af3864ff8333dbea1676e6b9d8647f19ea3ef7d58c974b5eccbaeb06d - SHA-1:
4161e11d23bf98a867ec93e803697e6f01a49658 - MD5:
5f70a8ac7a98abd9aeb55e0cc7bf7e4c - ssdeep:
3072:6sFw96d71Dvh8U94UM77meoT4g3tmNFBqvhv:6wea1DvZQ73oTCihv - TLSH:
T1243BE8433694BEDF9D454ACFB8AC340E191B88D2768130D819FC9F8E8859F20E85E55B - Submitted as: site.js
- File type: script · Size: 110332 bytes
- Verdict: suspicious (54/100)
Detections (0 of 53 engines)
No engine flagged this sample.
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://www.jqueryscript.net/blog/Best-Loading-Spinner-Indicator-jQuery-Plugins.html - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.w3.org/2000/svg
- http://www.w3.org/1999/xlink
- https://www.jqueryscript.net/blog/Best-Loading-Spinner-Indicator-jQuery-Plugins.html
Embedded domains
- g.top
- www.w3.org
- navigator.online
- www.jqueryscript.net
- this.colors.info
- dataset.top
- config.top
- bolbolkhan.com
- window.info
File paths
- C:\\fakepath\\
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report