SUSPICIOUS — GifImagePlugin.py
SUSPICIOUS — GifImagePlugin.py is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 0 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0cf9dd837ba23b412c95765aea4422bbf6e7c2210c6eefde91eab43d4308b0d5 - SHA-1:
7643bf5820b560ae74b6ca05142dbb8ba98f10f4 - MD5:
4f9760ed21efe34be37c46a434a2bfdc - ssdeep:
384:1fPV2NvdO+3bgDGNNGPe+ehpxW2FfqyUtRAsnjrmuBBqr51D6XJmKqhAs8Pz8a44:1fcXsaG0S3Bwr5SqhAs8r97 - TLSH:
T1A132838EA2D429AF8A5576CB6C7D113E4053E5DD134330D71ECAFE011426E40FCA96AB - Submitted as: GifImagePlugin.py
- File type: script · Size: 43596 bytes
- Verdict: suspicious (54/100)
Detections (0 of 53 engines)
No engine flagged this sample.
MITRE ATT&CK
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://www.matthewflickinger.com/lab/whatsinagif/bits_and_bytes.asp - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
1136 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- c.pki.goog
- ntp.ubuntu.com
- desktop-hsgcbep
- _dosvc._tcp.local
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- desktop-hsgcbep._dosvc._tcp.local
- 250.255.255.239.in-addr.arpa
Embedded URLs
- https://www.matthewflickinger.com/lab/whatsinagif/bits_and_bytes.asp
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787587654&P2=404&P3=2&P4=B1b8c5O7d82wVCgBL085BdcuDrScmnG%2fhXzJ2IA2bVm3p8MY2sx8hgRXsREhbGZtx0K6FruMGf7S518vf8aDjg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/45cd9142-6feb-4946-89e7-63e58fada30a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/45cd9142-6feb-4946-89e7-63e58fada30a?P1=1787587739&P2=404&P3=2&P4=bIVIv6qSswSzrd2v%2bcEa%2fq2XNCtR2Wjgb80CJ6%2fs%2bs%2b9G01uplYEdgxfLlIl6BV4iPF%2fOQ3baz0p9C2xaC9P%2fQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://c.pki.goog/r/gsr1.crl
- http://c.pki.goog/r/r4.crl
Embedded domains
- self.info
- im.info
- www.matthewflickinger.com
Embedded IP addresses
- 74.178.240.61
- 74.179.71.159
- 20.42.179.192
- 52.123.252.216
- 52.110.12.26
- 52.110.12.2
- 20.247.184.142
- 4.230.171.124
- 135.233.95.144
- 20.184.175.12
- 57.155.104.224
- 135.233.95.135
- 72.154.7.109
- 203.26.79.13
- 52.123.128.14
- 40.104.4.2
- 172.178.240.162
- 142.251.222.227
- 172.175.111.170
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report