SUSPICIOUS — 30781c9ea633021ee4a92768e3df0b462b529c24e143324878dcc841650d03a3
SUSPICIOUS — 30781c9ea633021ee4a92768e3df0b462b529c24e143324878dcc841650d03a3 is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
30781c9ea633021ee4a92768e3df0b462b529c24e143324878dcc841650d03a3 - SHA-1:
27b966b86506270257a20c06f6189b9e019207fc - MD5:
8c80bb944686190b0bf7d6098f871cfd - ssdeep:
768:OgeuCP6yeJr/5t31aPw6MdOGuKeockAty3YQlMOIm8E77VMDz/iVG7tPtEtVaYAt:l+P6yeJr/5t31aodveoc/QIQWOJ7VMDR - TLSH:
T19132B78672767CEF934A44ED2D88266F5C0F64DAB2403CE41FD4DF826982D52E42712B - Submitted as: 30781c9ea633021ee4a92768e3df0b462b529c24e143324878dcc841650d03a3
- File type: script · Size: 46543 bytes
- Verdict: suspicious (54/100)
Detections (2 of 50 engines)
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://dev.jquery.com/ticket/2752, http://en.wikipedia.org/wiki/Same_origin_policy, http://docs.jquery.com/Tutorials:Introducing_$ - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://dev.jquery.com/ticket/2752
- https://github.com/malsup/form/commit/588306aedba1de01388032d5f42a60159eea9228#commitcomment-2180219
- http://groups.google.com/group/jquery-dev/browse_thread/thread/36395b7ab510dd5d
- http://en.wikipedia.org/wiki/Same_origin_policy
- http://docs.jquery.com/Tutorials:Introducing_$
- http://www.w3.org/TR/html4/interact/forms.html#successful-controls
Embedded domains
- dev.jquery.com
- github.com
- groups.google.com
- sub.name
- en.wikipedia.org
- e.name
- docs.jquery.com
- offset.top
- el.name
- input.name
- this.name
- www.w3.org
- campusify.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report