SUSPICIOUS — 33a3380a4e659d637bcd5ee76cba5e70a55d857873d7a9ab8d919c82f3fb323c
SUSPICIOUS — 33a3380a4e659d637bcd5ee76cba5e70a55d857873d7a9ab8d919c82f3fb323c is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
33a3380a4e659d637bcd5ee76cba5e70a55d857873d7a9ab8d919c82f3fb323c - SHA-1:
606defd587034a8a2b1569d3d36d0fb9e2055d6f - MD5:
963e73a0730e35bc71ef7e7cd9bcaf0c - ssdeep:
48:xFiRbsU5eSsXK0tAAr4L+cd3ea5LoU0SgppC2h0Aqbrc6mS/IkeWcQbhLJfYK687:ziRt5T/E6V3eCoUUppC2DqXclS+2fP60 - TLSH:
T1D71663C1B4491AE8C45FD722FF8BB4533F8FDA16A26740C5828C475324A58C2AD1922A - Submitted as: 33a3380a4e659d637bcd5ee76cba5e70a55d857873d7a9ab8d919c82f3fb323c
- File type: script · Size: 2929 bytes
- Verdict: suspicious (54/100)
Detections (2 of 50 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://dreamerslab.com/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://dreamerslab.com/
Embedded domains
- dreamerslab.com
- rusfishexpo.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report