SUSPICIOUS — 4f25c9a6c80b62bcb0e8119554134d46dc0edbb86a98f0fe81599f821bc05a2a
SUSPICIOUS — 4f25c9a6c80b62bcb0e8119554134d46dc0edbb86a98f0fe81599f821bc05a2a is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
4f25c9a6c80b62bcb0e8119554134d46dc0edbb86a98f0fe81599f821bc05a2a - SHA-1:
a0f8af2b8201cac826085ac9ace152e2987eb259 - MD5:
08d2736092255c9902833c4d62c4b17d - ssdeep:
192:sNTBY0jWBoYf0/VlXFgRPCk3psolNd882K6ANEjCWvCps2MzfPku:sNTBFWBoYfqVl1+rZsolNd882K6ANEjV - TLSH:
T17222508F38887D9C8C0E01A76DC75867BB1B4E08766988E983FDE792EDB05C51C24496 - Submitted as: 4f25c9a6c80b62bcb0e8119554134d46dc0edbb86a98f0fe81599f821bc05a2a
- File type: script · Size: 10013 bytes
- Verdict: suspicious (54/100)
Detections (2 of 50 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://jqueryui.com, http://jquery.org/license, http://api.jqueryui.com/autocomplete/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://jqueryui.com
- http://jquery.org/license
- http://api.jqueryui.com/autocomplete/
Embedded domains
- jqueryui.com
- jquery.org
- api.jqueryui.com
- nesimaresort.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report