SUSPICIOUS — 243872184-lbx__pt_br.js
SUSPICIOUS — 243872184-lbx__pt_br.js is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 0 of 53 detection engines flagged it.
Identification
- SHA-256:
1d643e4b93da79c302afdc8dab7b357a069ed1ad63a7b96449bad25bb13d35a0 - SHA-1:
64732e36a60ee5abc5c097e7020aeec48393d446 - MD5:
154430a2888a000966e3ce0bf5e409f1 - ssdeep:
3072:Sx/JfhbhAob0kjHtJnOK0PS+pWItHhUrw+YK+2S6ai0/GH8UClRjLWsiOlKpEcyS:SxxFhDj+dPSn7nS61TcwpE9zpjJm - TLSH:
T19A4972DE3986EECEDC4E70AE7D4CA853B3039E54B76290E082BEC32558E58D43D54825 - Submitted as: 243872184-lbx__pt_br.js
- File type: script · Size: 405893 bytes
- Verdict: suspicious (54/100)
Detections (0 of 53 engines)
No engine flagged this sample.
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated powershell script: dynamic-exec, defense-evasion (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://flickr.com/photos/, 2.0.0.11 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://photos.google.com/lightbox/photoid
- http://flickr.com/photos/
- http://picasaweb.google.com/
- http://google.com/profiles/media/container
- http://google.com/profiles/media/provider
- http://www.google.com/intl/
Embedded domains
- photos.google.com
- pe.prototype.name
- a.de
- m.sg
- hh.prototype.gg
- this.ch
- lh.prototype.gg
- a.ch
- b.ch
- this.fi
- qh.prototype.gg
- a.fi
- a.gg
- m.nl
- this.nl
- m.cn
- this.cf
- a.cf
- a.cn
- this.cn
- bi.prototype.cn
- this.it
- m.it
- this.me
- m.me
Embedded IP addresses
- 2.0.0.11
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report