SUSPICIOUS — 1a16851b56dd92d7cd00fc3e6fc89763fd77180d161ea49d19cddc92d189fa37
SUSPICIOUS — 1a16851b56dd92d7cd00fc3e6fc89763fd77180d161ea49d19cddc92d189fa37 is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (59/100). 1 of 50 detection engines flagged it.
Identification
- SHA-256:
1a16851b56dd92d7cd00fc3e6fc89763fd77180d161ea49d19cddc92d189fa37 - SHA-1:
3cb3dc968c5654321b43f0f2f94eadeab83f5e79 - MD5:
f99b59c8fe62d1a802ce114a4f52278b - ssdeep:
768:Tb9bMI9Ob96tfg8WzC56/bO9Y6Agc1yEprPxJpArPxJpit3/vkhZUIA+pYjT/qY9:Tb9YI9Ob9h24/bOvHjs - TLSH:
T1502D6523BD18BEDF6419199D25601C6E1C87C8E635203CE849E8AF48C554FF2D8CAD9B - Submitted as: 1a16851b56dd92d7cd00fc3e6fc89763fd77180d161ea49d19cddc92d189fa37
- File type: script · Size: 29447 bytes
- Verdict: suspicious (59/100)
Detections (1 of 50 engines)
- Microsoft Defender: Trojan:JS/Redirector.AYLB!MTB
Why this verdict
The suspicious score of 59/100 is the fusion of 4 weighted signals:
- Obfuscated javascript script: dynamic-exec (layers: char-code+concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://www.pinterest.com/pin/create/button/?url=, https://for.dontkinhooot.tw/stat.js, https://main.travelfornamewalking.ga/js.php?v=352 - static signal, weight 0.35, confidence 0.60
- Contacted 6 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
842 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ntp.ubuntu.com
- desktop-hsgcbep
- 224.0.0.251
- ff02::fb
- ff02::1:3
- 224.0.0.252
- 10.240.0.1
- 10.240.0.255
- ff02::16
- ff02::1:ff4c:1d1d
- 135.233.95.80 US · Des Moines · AS8075 Microsoft Limited
- 224.0.0.22
- ff02::1:2
- ff02::1:ff12:3456
- ff02::1
- ff02::2
Dropped files
- tmp_tmp.ltbFR3asF7 -
4518baacec1a64efbd79da125a460501571c69ab0371d7f7e32d90da62f78776
Embedded URLs
- http://www.pinterest.com/pin/create/button/?url=
- https://for.dontkinhooot.tw/stat.js
- https://main.travelfornamewalking.ga/js.php?v=352
Embedded domains
- www.pinterest.com
- for.dontkinhooot.tw
- main.travelfornamewalking.ga
Embedded IP addresses
- 135.233.95.80
- 74.178.76.128
- 4.150.223.108
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report