SUSPICIOUS — 4edd6e0bd9a145346a9777c16a62a2e20e0dbbf07e4e8db43417a62ee96ab0b7
SUSPICIOUS — 4edd6e0bd9a145346a9777c16a62a2e20e0dbbf07e4e8db43417a62ee96ab0b7 is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (59/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
4edd6e0bd9a145346a9777c16a62a2e20e0dbbf07e4e8db43417a62ee96ab0b7 - SHA-1:
872ea5c1853148b38074a2d278bf013e8c4eb17f - MD5:
9292c80bde1d05e39c4d25a35500c93f - ssdeep:
3072:0kvBNnLO1wG0qOOO8D5BnAcKcv1/i/fXMS6PuQr1Q7SV7opGY:dLODl6c/KuS6Pu - TLSH:
T15E44D89F384D7C9C8C0D46AB2DCDE96EB7135E15B899C0C882FDD748E9745B008988E9 - Submitted as: 4edd6e0bd9a145346a9777c16a62a2e20e0dbbf07e4e8db43417a62ee96ab0b7
- File type: script · Size: 255457 bytes
- Verdict: suspicious (59/100)
Detections (3 of 50 engines)
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Emsisoft (Emergency Kit): GT:JS.Injected.1.B1AE6AAB
Why this verdict
The suspicious score of 59/100 is the fusion of 4 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://jqueryui.com - static signal, weight 0.35, confidence 0.60
- Contacted 3 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
870 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- 250.255.255.239.in-addr.arpa
- desktop-hsgcbep
- ntp.ubuntu.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 224.0.0.251
- ff02::fb
- ff02::1:3
- 224.0.0.252
- 169.254.255.255
- 10.240.0.255
- 10.240.0.1
- 91.189.91.157
- 185.125.190.58
- 224.0.0.22
- ff02::1:ff12:3456
- ff02::16
- 239.255.255.250
Dropped files
- tmp_tmp.3DAfzDgThA -
940586484df45770ca651abf21fb364a68e3c41457da30ca3744831a2b1036cb
Embedded URLs
- http://jqueryui.com
Embedded domains
- jqueryui.com
- m.top
- g.top
- s.offset.top
- t.top
- n.offset.top
- n.name
- style.top
- this.position.top
- this.offset.click.top
- e.top
- this.margins.top
- this.offset.relative.top-this.offset.parent.top
- this.offset.relative.top
- this.offset.parent.top
- this.offset.scroll.top
- s.top
- n-this.offset.click.top
- l-this.offset.click.top-this.offset.relative.top-this.offset.parent.top
- o.offset.click.top
- s.offset.click.top
- o.offset.parent.top
- s.offset.parent.top-o.offset.parent.top
- i.top
- i.offset.top
Embedded IP addresses
- 135.232.92.137
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report