MALICIOUS — 4f5105243d55f7e149cfff415d648d81fcf18bf3e324bdf738957b3ff2faf1ce
MALICIOUS — 4f5105243d55f7e149cfff415d648d81fcf18bf3e324bdf738957b3ff2faf1ce is a script sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (72/100). 2 of 54 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
4f5105243d55f7e149cfff415d648d81fcf18bf3e324bdf738957b3ff2faf1ce - SHA-1:
040f3bfd23457f709a6250060d174ea819b6944e - MD5:
a019f9f005df6b9090b996551b94dd8a - ssdeep:
48:0g0JsGlLCCXUIQG/wrkxN6LisX8wTUK8KSITRH5c4cUs39M89+EwGSdHPF4Yle3K:chLCUUISkD6NX8+U2SITRG4dsa89BwGs - TLSH:
T1E915825792A848673A53B15E8B98130DFF93D43C76D4E2422BC25F82C64F3422C374A9 - Submitted as: 4f5105243d55f7e149cfff415d648d81fcf18bf3e324bdf738957b3ff2faf1ce
- File type: script · Size: 2537 bytes
- Verdict: malicious (72/100)
Detections (2 of 54 engines)
- Microsoft Defender: Trojan:JS/Nemucod.SMQ!MTB
- Kaspersky (KVRT): HEUR:Trojan-Downloader.Script.SLoad.gen
MITRE ATT&CK
Why this verdict
The malicious score of 72/100 is the fusion of 2 weighted signals:
- Microsoft Defender flagged Trojan:JS/Nemucod.SMQ!MTB (rule
Trojan:JS/Nemucod.SMQ!MTB) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan-Downloader.Script.SLoad.gen (rule
HEUR:Trojan-Downloader.Script.SLoad.gen) - engine signal, weight 0.55, confidence 0.85
Dynamic analysis (windows)
5623 behavior events · 2 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- 0e604597.upstream.fishslayerjigco.com
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.209
- 23.11.37.157
- 40.126.14.164
- 52.230.59.222 SG · Singapore · AS8075 Microsoft Corporation
- 23.33.238.135
- 52.110.12.31 AU · Sydney · AS8075 Microsoft Corporation
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
- 23.33.238.173
- 150.171.28.11
- 135.233.45.221 US · Des Moines · AS8075 Microsoft Limited
Dropped files
- 469553667a131d0ab764f3f0cb6cc050125d3c8ede7f98258a3501d353ccc42a -
469553667a131d0ab764f3f0cb6cc050125d3c8ede7f98258a3501d353ccc42a
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- 0e604597.upstream.fishslayerjigco.com
Embedded IP addresses
- 203.26.79.13
- 51.116.253.170
- 52.230.59.222
- 52.110.12.31
- 4.230.171.124
- 135.233.45.221
- 57.155.104.224
- 72.153.5.137
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report