SUSPICIOUS — 502f32b5805198b365ea34040934582b713b349564c9b19ea6456ed09294e7cb
SUSPICIOUS — 502f32b5805198b365ea34040934582b713b349564c9b19ea6456ed09294e7cb is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 0 of 50 detection engines flagged it.
Identification
- SHA-256:
502f32b5805198b365ea34040934582b713b349564c9b19ea6456ed09294e7cb - SHA-1:
efb781119f345c9e0e200195cf86be84b43bce74 - MD5:
3d22b81722817fb45c9f08195c949716 - ssdeep:
1536:PqWRwt+dfC9mASAHAVALAqAs0Je4A4APArAlY4o5Jb:PqWRwodK9mASAHAVALAqAs2e4A4APAr5 - TLSH:
T1E837411467F0288FC7814540A845185C9CA6BEDBB92271E68F6DEF4F114CEA7F0B85A3 - Submitted as: 502f32b5805198b365ea34040934582b713b349564c9b19ea6456ed09294e7cb
- File type: script · Size: 72620 bytes
- Verdict: suspicious (54/100)
Detections (0 of 50 engines)
No engine flagged this sample.
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated powershell script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://www.ritecoupons.com/public/images/icon/favicon.png, https://www.googletagmanager.com/gtag/js?id=UA-103252605-1, https://www.ritecoupons.com/public/css/bootstrap-theme.min.css - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://www.ritecoupons.com/public/images/icon/favicon.png
- https://www.googletagmanager.com/gtag/js?id=UA-103252605-1
- https://www.ritecoupons.com/public/css/bootstrap-theme.min.css
- https://www.ritecoupons.com/public/css/custom.css
- https://www.ritecoupons.com/public/css/coupon.css
- https://www.ritecoupons.com/public/css/header.css
- https://www.ritecoupons.com/public/css/style.css
- https://www.ritecoupons.com/public/css/font-awesome.min.css
- https://maxcdn.bootstrapcdn.com/bootstrap/3.4.0/css/bootstrap.min.css
- https://stackpath.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.css
- https://www.ritecoupons.com/public/css/font-awesome.css
- https://www.ritecoupons.com/public/css/templates_css.css
- https://fonts.googleapis.com/css?family=Roboto
- https://www.ritecoupons.com/public/images/logo/logo.png
- https://www.ritecoupons.com/storesSearch
- https://www.ritecoupons.com/categories/back-to-school-discount-coupon-codes.html
- https://ajax.googleapis.com/ajax/libs/jquery/3.1.0/jquery.min.js
- https://maxcdn.bootstrapcdn.com/bootstrap/3.3.6/css/bootstrap.min.css
- https://maxcdn.bootstrapcdn.com/bootstrap/3.3.7/js/bootstrap.min.js
- https://www.ritecoupons.com/autocomplete/fetch
- http://schema.org/BreadcrumbList
- http://schema.org/ListItem
- https://shareasale.com/r.cfm?b=592994&
- https://www.ritecoupons.com/stores/sainsmart-discount-coupon-codes.html
- https://www.ritecoupons.com/public/images/icon/free.png
Embedded domains
- www.ritecoupons.com
- www.googletagmanager.com
- maxcdn.bootstrapcdn.com
- stackpath.bootstrapcdn.com
- code.jquery.com
- fonts.googleapis.com
- ajax.googleapis.com
- schema.org
- riteportal.ritecoupons.com
- shareasale.com
- www.facebook.com
- www.pinterest.com
- twitter.com
Embedded IP addresses
- 09.1.23.02
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report