MALICIOUS — 1c70d6c57ca876bbe39d09ef8c7a4293910271a13707109712543fe2a28e9bfc.js
MALICIOUS — 1c70d6c57ca876bbe39d09ef8c7a4293910271a13707109712543fe2a28e9bfc.js is a script sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (74/100), attributed to the execute family. 5 of 51 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1c70d6c57ca876bbe39d09ef8c7a4293910271a13707109712543fe2a28e9bfc - SHA-1:
41f7874c4287aa3005749be207fd41e934f3e61c - MD5:
a82457fed3f9f435778b6f89172ce519 - ssdeep:
24576:s+9fxoTL78pFibaIEazi9tTtcb3eugEboehk8OtxNjiq0sr3FOEZuGA/OUzmmsW8:RxwrKiK+e - TLSH:
T10C64AFCEA5CF7369E67B2967A7644A21321583C8B52316187052D803ED5FEBEE3CC484 - Submitted as: 1c70d6c57ca876bbe39d09ef8c7a4293910271a13707109712543fe2a28e9bfc.js
- File type: script · Size: 5493061 bytes
- Verdict: malicious (74/100) · Family: execute
Source: MalwareBazaar · first seen 2026-07-27T00:00:00.000Z · SHA-256 verified
Detections (5 of 51 engines)
- capa (capabilities): execute via PowerShell
- YARA: Trellix/McAfee ATR: ATR_BlackCat_ALPHV
- Kaspersky (KVRT): HEUR:Trojan-Downloader.Script.SLoad.gen
- Microsoft Defender: Trojan:JS/VIPKeyLogger.BAA!MTB
- Emsisoft (Emergency Kit): Trojan.GenericKD.80949346
MITRE ATT&CK
Why this verdict
The malicious score of 74/100 is the fusion of 5 weighted signals:
- Obfuscated powershell script: dynamic-exec, encoded-command, defense-evasion (layers: base64+concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - YARA: Trellix/McAfee ATR flagged ATR_BlackCat_ALPHV (rule
ATR_BlackCat_ALPHV) - engine signal, weight 0.35, confidence 0.70 - Contacted 2 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Contacted 2 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (linux)
845 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- entropy.ubuntu.com
- ntp.ubuntu.com
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 185.125.189.54
- 10.240.0.1
- ff02::1:3
- 224.0.0.252
- 10.240.0.255
- ff02::16
- ff02::fb
- 224.0.0.251
- ff02::1:ff12:3456
- 255.255.255.255
- ff02::1:2
- 224.0.0.22
- ff02::2
Dropped files
- tmp_tmp.1TZCk23hJE -
00c70fc0bdee159853d12817b3e5c9ed9bffed6b75a2639132b10b659ce9b2b0
More execute samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report