SUSPICIOUS — 4110c8d1f595e6b95bcd642d81d93cc092ce9b04d1e715401c658c52bdedf251
SUSPICIOUS — 4110c8d1f595e6b95bcd642d81d93cc092ce9b04d1e715401c658c52bdedf251 is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
4110c8d1f595e6b95bcd642d81d93cc092ce9b04d1e715401c658c52bdedf251 - SHA-1:
4c1e8d60d7206254750d2272c1208ab27de78da5 - MD5:
ac1a189407e34c227e831eeb03c9a1f0 - ssdeep:
1536:dWkvcMg2KWspIpiHJO986EzOQth8ZqLx2nPce0P4NnVOjaubEs9D6HD6kx4iDz3/:FKWspIVghth8ZE0ce0P4NniD6HD6kx4s - TLSH:
T10A39C78D3CC96F8CCD0D51D63ECCA99A77239A5576A9D4E8C3BCE750A9B08F04C8441A - Submitted as: 4110c8d1f595e6b95bcd642d81d93cc092ce9b04d1e715401c658c52bdedf251
- File type: script · Size: 86400 bytes
- Verdict: suspicious (54/100)
Detections (2 of 50 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated powershell script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://css-tricks.com, http://daverupert.com, http://www.alistapart.com/articles/creating-intrinsic-ratios-for-video/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://github.com/nicinabox/superslides
- https://github.com/imakewebthings/jquery-waypoints/blob/master/licenses.txt
- https://github.com/mhuggins/jquery-countTo
- http://css-tricks.com
- http://daverupert.com
- http://www.alistapart.com/articles/creating-intrinsic-ratios-for-video/
- http://sam.zoy.org/wtfpl/
- http://www.ianlunn.co.uk/plugins/jquery-parallax/
- http://www.opensource.org/licenses/mit-license.php
- http://www.gnu.org/licenses/gpl.html
- http://www.owlgraphic.com/owlcarousel/
- http://isotope.metafizzy.co
- http://bit.ly/getsizebug1
Embedded domains
- github.com
- e.top
- this.options.to
- css-tricks.com
- daverupert.com
- www.alistapart.com
- sam.zoy.org
- player.vimeo.com
- youtube.com
- youtube-nocookie.com
- kickstarter.com
- www.ianlunn.co.uk
- www.opensource.org
- www.gnu.org
- www.owlgraphic.com
- y-e.top
- isotope.metafizzy.co
- bit.ly
- t.to
- t.top
- n.top
- odszkodowanialuton.co.uk
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report