SUSPICIOUS — 35e605123ca4cb0903beadd0926d679abd79c36b52e98dce8c0c15752416f281
SUSPICIOUS — 35e605123ca4cb0903beadd0926d679abd79c36b52e98dce8c0c15752416f281 is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (69/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
35e605123ca4cb0903beadd0926d679abd79c36b52e98dce8c0c15752416f281 - SHA-1:
4f79294ba7c133755c859785f1cd1d3c38051a37 - MD5:
7a2ebebd2edcb5963aacd0f2f0d2d3a4 - ssdeep:
48:UgVOqutOX4OO5QngppC2To45c6mS/IkeWcQbhLJfYK68ZqzeeA:JVObOX4OpgppC2nclS+2fP68ku - TLSH:
T1661522D164562BF4D54EA313FFC7B5033F8EDB22629340C6CA4C655324A58827E18B39 - Submitted as: 35e605123ca4cb0903beadd0926d679abd79c36b52e98dce8c0c15752416f281
- File type: script · Size: 2237 bytes
- Verdict: suspicious (69/100)
Detections (2 of 50 engines)
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
Why this verdict
The suspicious score of 69/100 is the fusion of 2 weighted signals:
- Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- everydayagency.co.uk
- bitcoinbro.atouchoflovefoundation.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report