SUSPICIOUS — 2c62d2460b0027fc1384d5e1ff0003de9a19fdf6bc32abbfdecc6ef5a0648fac
SUSPICIOUS — 2c62d2460b0027fc1384d5e1ff0003de9a19fdf6bc32abbfdecc6ef5a0648fac is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
2c62d2460b0027fc1384d5e1ff0003de9a19fdf6bc32abbfdecc6ef5a0648fac - SHA-1:
242979ae7b4f3829bf5b4ee95de12cd81956d61f - MD5:
332ef82a172291fc9282dc438a5336c4 - ssdeep:
768:aRxxDvxXz/mlVKHrVehz883QEAzDc5GDTSebsvZiVvKW6OeQ5oedXLf6ETv3x+F6:aRxx7xXzJrVnjEAzDc58TSebsRiVvKWR - TLSH:
T18730E726360CE68CC84807F77EF47629F122956699F354C880BDD271BEACC71A885D6C - Submitted as: 2c62d2460b0027fc1384d5e1ff0003de9a19fdf6bc32abbfdecc6ef5a0648fac
- File type: script · Size: 38389 bytes
- Verdict: suspicious (54/100)
Detections (3 of 50 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Emsisoft (Emergency Kit): Trojan.Generic.31252235
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://www.youtube-nocookie.com, https://player.vimeo.com/api/player.js, https://www.youtube.com/iframe_api - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://www.youtube-nocookie.com
- https://player.vimeo.com/api/player.js
- https://www.youtube.com/iframe_api
Embedded domains
- www.youtube-nocookie.com
- vimeo.com
- player.vimeo.com
- www.youtube.com
- spantechpt.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report