CLEAN — 4048af9498d215280ad829856a8c5e9105dd50dd851b7f1e7b026b78cd864fed
CLEAN — 4048af9498d215280ad829856a8c5e9105dd50dd851b7f1e7b026b78cd864fed is a script sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (21/100). 0 of 53 detection engines flagged it.
Identification
- SHA-256:
4048af9498d215280ad829856a8c5e9105dd50dd851b7f1e7b026b78cd864fed - SHA-1:
80e61a8bd1a4932616d18c6a8ceda79ef6a4bd68 - MD5:
ce39fce18f092c30b044e9436f1d4660 - ssdeep:
96:m5Ev4FfbFSCGG/iSrXZlCytT81FPRVSLj:yEEfbFSCGciSrDCytT81FPRVSLj - TLSH:
T14B1ADFF69B317EFFAF8635C5690D28AF0A0320C3B8016965DA04A9C55C63C991F1CC9C - Submitted as: 4048af9498d215280ad829856a8c5e9105dd50dd851b7f1e7b026b78cd864fed
- File type: script · Size: 4453 bytes
- Verdict: clean (21/100)
Detections (0 of 53 engines)
No engine flagged this sample.
Why this verdict
The clean score of 21/100 is the fusion of 1 weighted signal:
- Embedded network infrastructure: http://www.best-deals-products.com/f/gstats - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
1105 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- desktop-hsgcbep
- WORKGROUP
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787925688&P2=404&P3=2&P4=EomaJDYznZ%2b6oaYb5eV6kz%2bjtUyguCtVTWdjn6j458gcymE%2fJHLYUyRHwcrAZngJfAdCvLcHZGC1nKu9nP6xoA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/51d86688-616b-47e3-abeb-3df16a1583c5?P1=1787925740&P2=404&P3=2&P4=dvKnhSJBvvQr8siRc4tmpy9VUKvBDTZP14GZNu6sQI4jd9GCZMhtK5nbBnCDJSnmk6EFDjGNMFoUuruXDLDSoA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded URLs
- http://www.best-deals-products.com/f/gstats
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787925688&P2=404&P3=2&P4=EomaJDYznZ%2b6oaYb5eV6kz%2bjtUyguCtVTWdjn6j458gcymE%2fJHLYUyRHwcrAZngJfAdCvLcHZGC1nKu9nP6xoA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/51d86688-616b-47e3-abeb-3df16a1583c5?P1=1787925740&P2=404&P3=2&P4=dvKnhSJBvvQr8siRc4tmpy9VUKvBDTZP14GZNu6sQI4jd9GCZMhtK5nbBnCDJSnmk6EFDjGNMFoUuruXDLDSoA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/b56480f9-8215-4de7-ba7e-8e690088d21d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5?P1=1787322480&P2=404&P3=2&P4=nYwFuRLQyxhXLVw5P5ntgaFJZ2RBaR4Fy3I6XJjeeqo%2brbtqbsoZh2%2bOCMIaqU4H35iOVR3v%2fxrmVa50wK0aZw%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/b56480f9-8215-4de7-ba7e-8e690088d21d?P1=1787321975&P2=404&P3=2&P4=BFG2h%2f4XoakzgF1nDUqS3bHfwY7qm9ms8jEVSuKxDLDy%2bm9jpAbkVgLcOEcYSYUyRVjrT7nJLrE95hlPVJnR9Q%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- www.best-deals-products.com
Embedded IP addresses
- 172.215.188.232
- 4.150.223.100
- 172.172.255.218
- 4.150.223.105
- 52.123.252.197
- 4.144.132.114
- 4.247.188.233
- 52.110.12.31
- 4.230.171.124
- 20.42.73.25
- 20.76.201.171
- 135.233.95.144
- 52.123.128.14
- 74.178.76.128
- 52.123.252.248
- 72.153.5.137
- 203.26.79.13
- 52.123.252.232
- 40.84.97.4
- 92.223.78.30
- 74.178.76.44
- 52.168.117.170
- 20.184.175.19
- 172.175.111.170
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report