SUSPICIOUS — 2286b060862784ecbfed5d397b0efbe9e8260bedd8527a6242463fe8d4b542f0
SUSPICIOUS — 2286b060862784ecbfed5d397b0efbe9e8260bedd8527a6242463fe8d4b542f0 is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (59/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
2286b060862784ecbfed5d397b0efbe9e8260bedd8527a6242463fe8d4b542f0 - SHA-1:
8021ec01ee8f5d96dcb5e5e0829b68c48262a578 - MD5:
253357f28d1af3892f85339901562824 - ssdeep:
768:f6tj9tumwoSxNreZp3vzRzwIjg2GsuzSglP70S:f6Ra/reZp3vzR5jg2GsuzTF70S - TLSH:
T1C32E410E3D8D7A9DCC4978436CEC8197722A9B811E7494ED83BED34ABCB45E89C0854D - Submitted as: 2286b060862784ecbfed5d397b0efbe9e8260bedd8527a6242463fe8d4b542f0
- File type: script · Size: 31004 bytes
- Verdict: suspicious (59/100)
Detections (2 of 50 engines)
- Microsoft Defender: Trojan:JS/Cryxos.AXCA!MTB
- Emsisoft (Emergency Kit): GT:JS.Injected.2.0A92AE37
Why this verdict
The suspicious score of 59/100 is the fusion of 4 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://getharvest.com - static signal, weight 0.35, confidence 0.60
- Contacted 2 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
910 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- desktop-hsgcbep
- 250.255.255.239.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ntp.ubuntu.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ff02::1:3
- 224.0.0.252
- 224.0.0.251
- ff02::fb
- 10.240.0.255
- 239.255.255.250
- 10.240.0.1
- ff02::16
- 169.254.255.255
- 185.125.190.58
- 224.0.0.22
- 74.178.240.61 NL · Amsterdam · AS8075 Microsoft Corporation
- ff02::2
Dropped files
- tmp_tmp.M8uuPe0dCl -
0f2addae45850017d6035d86a0700d3fff664fdb1f92239fb09d9cba0da2ae42
Embedded URLs
- http://getharvest.com
- https://github.com/harvesthq/chosen
- https://github.com/harvesthq/chosen/blob/master/LICENSE.md
Embedded domains
- getharvest.com
- github.com
- li.no
Embedded IP addresses
- 74.178.240.61
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report