MALICIOUS — 1bd229256136c235c942bdcf5f1c1b2523c6e339ee8efecf71773a9f9c2a49bd
MALICIOUS — 1bd229256136c235c942bdcf5f1c1b2523c6e339ee8efecf71773a9f9c2a49bd is a script sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (91/100), attributed to the Base64 family. 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1bd229256136c235c942bdcf5f1c1b2523c6e339ee8efecf71773a9f9c2a49bd - SHA-1:
88d932a601027199869fca5b7fb846ad97851f84 - MD5:
5369ba3727f6cb3d7432881f740b9519 - ssdeep:
6:snlNjv2HSgAokknQqhzaLnHiO6snkYpXkyAhla2NertWt0UslffSdmJQ/qmOjUiC:snlNjeygA5kvILnHiqn9uyAhfyRlf6EY - TLSH:
T1BA0EC01C6FC005468AC5BAA3806F14DCCAE8334D48D735A006F0F2681A35A5222013E4 - Submitted as: 1bd229256136c235c942bdcf5f1c1b2523c6e339ee8efecf71773a9f9c2a49bd
- File type: script · Size: 372 bytes
- Verdict: malicious (91/100) · Family: Base64
Detections (3 of 50 engines)
- YARA: MalwareAnalyser built-in: Suspicious_PowerShell_Download_Exec
- capa (capabilities): capability:execution/powershell
- YARA: MalwareAnalyser community pack: TL_Base64_EncodedCommand
MITRE ATT&CK
YARA
- Suspicious_PowerShell_Download_Exec
Why this verdict
The malicious score of 91/100 is the fusion of 5 weighted signals:
- Encoded/hidden PowerShell download-and-exec (rule
Suspicious_PowerShell_Download_Exec) - yara signal, weight 0.70, confidence 0.90 - Obfuscated powershell script: download, hidden-window, defense-evasion (layers: powershell-encodedcommand+base64) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - YARA: MalwareAnalyser community pack flagged TL_Base64_EncodedCommand (rule
TL_Base64_EncodedCommand) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://worldnit.com/nigga.exe - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://worldnit.com/nigga.exe
Embedded domains
- worldnit.com
More Base64 samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report