MALICIOUS — 2680dba92ea10cdab7a739103bc4b7fda70fe37276b772e1436917ad39805d9d
MALICIOUS — 2680dba92ea10cdab7a739103bc4b7fda70fe37276b772e1436917ad39805d9d is a script sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100). 2 of 54 detection engines flagged it.
Identification
- SHA-256:
2680dba92ea10cdab7a739103bc4b7fda70fe37276b772e1436917ad39805d9d - SHA-1:
010f40b6bddaed08c2872faf8a1a5a6e60b91054 - MD5:
3b2fc09ea1f2f4eb9871420670140d29 - ssdeep:
96:n5dI1DIfNxoDfLiDoeduQfAGfaqQ9fk6KMvY5Y52cQGiqwXmuz:II1yDji0cuQWD9M6W5Y52cQLFXV - TLSH:
T1FA1C3EE54B2024CFC3D06C664851697EA70E90FBD1617BCD16E2412C3C7AAD0D1A4AAB - Submitted as: 2680dba92ea10cdab7a739103bc4b7fda70fe37276b772e1436917ad39805d9d
- File type: script · Size: 5562 bytes
- Verdict: malicious (87/100)
Detections (2 of 54 engines)
- Emsisoft (Emergency Kit): Trojan.Script.EBC
- Kaspersky (KVRT): HEUR:Exploit.Java.CVE-2019-2725.gen
Why this verdict
The malicious score of 87/100 is the fusion of 4 weighted signals:
- Emsisoft (Emergency Kit) flagged Trojan.Script.EBC (rule
Trojan.Script.EBC) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Exploit.Java.CVE-2019-2725.gen (rule
HEUR:Exploit.Java.CVE-2019-2725.gen) - engine signal, weight 0.55, confidence 0.85 - Obfuscated powershell script: download, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://www.bea.com/async/AsyncResponseService, http://UeR.ReiyKiQ.ir/download.exe - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
1120 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- desktop-hsgcbep(2)._dosvc._tcp.local
- desktop-hsgcbep(3)._dosvc._tcp.local
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.209
- 23.11.37.157
- 20.190.142.164
- 20.247.184.197 SG · Singapore · AS8075 Microsoft Corporation
- 52.123.252.212 AU · Sydney · AS8075 Microsoft Corporation
- 52.110.12.8 AU · Sydney · AS8075 Microsoft Corporation
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
Embedded URLs
- http://schemas.xmlsoap.org/soap/envelope/
- http://www.w3.org/2005/08/addressing
- http://www.bea.com/async/AsyncResponseService
- http://bea.com/2004/06/soap/workarea/
- http://UeR.ReiyKiQ.ir/download.exe
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- schemas.xmlsoap.org
- www.w3.org
- www.bea.com
- bea.com
- uer.reiykiq.ir
Embedded IP addresses
- 4.247.188.224
- 20.184.175.12
- 20.42.179.192
- 40.84.97.4
- 20.247.184.197
- 52.123.252.212
- 52.110.12.8
- 4.230.171.124
- 74.178.76.128
- 72.153.5.132
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report