SUSPICIOUS — 2fdfbdc3767a5c79731d3a5a89e0b4903040d31bb71659453cd74d8241cffc4f
SUSPICIOUS — 2fdfbdc3767a5c79731d3a5a89e0b4903040d31bb71659453cd74d8241cffc4f is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
2fdfbdc3767a5c79731d3a5a89e0b4903040d31bb71659453cd74d8241cffc4f - SHA-1:
1ca02ef83efe2f0bb4f3c70ef1a768747338919a - MD5:
3f6d66ec768ab0779e5d5ee90bd0d18a - ssdeep:
1536:MtUO/3VOjkDIzQOwQMThyf8PBsvXhGvZ829abjEiVodHYCrf9mnKJJZ:MAQOwQn8PBsvRGZ829abI/H0nMZ - TLSH:
T1B03A414B3CC95A988D4D4422AED8249EFB534E2130443498D3B4D7DBCDDCBAA587886F - Submitted as: 2fdfbdc3767a5c79731d3a5a89e0b4903040d31bb71659453cd74d8241cffc4f
- File type: script · Size: 101095 bytes
- Verdict: suspicious (54/100)
Detections (2 of 53 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated powershell script: dynamic-exec, defense-evasion (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://www.youtube.com/iframe_api, http://a.vimeocdn.com/js/froogaloop2.min.js - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://unscriptable.com/2009/03/20/debouncing-javascript-methods/
- https://www.youtube.com/iframe_api
- https://github.com/jaz303/tipsy
- http://a.vimeocdn.com/js/froogaloop2.min.js
Embedded domains
- unscriptable.com
- settings.no
- www.youtube.com
- github.com
- e.top
- b.live
- a.vimeocdn.com
- player.vimeo.com
- madtravel.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report