SUSPICIOUS — 50f6166d114a15e1fa03ae0796a24ddbe11de70f41de75cfca4dafddc2170952
SUSPICIOUS — 50f6166d114a15e1fa03ae0796a24ddbe11de70f41de75cfca4dafddc2170952 is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (41/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
50f6166d114a15e1fa03ae0796a24ddbe11de70f41de75cfca4dafddc2170952 - SHA-1:
f403acec4c0a987d88dbfa90972e51dc27062129 - MD5:
35f2e8dcdf718e63f9547bea865f2c0a - ssdeep:
768:Q6GFYN0KQXcXmmqLfB7lXezDCEhACKv4u:YmrQNLZ7lXez2/vH - TLSH:
T119333D6738F97AE4D40CD40F3DF65ED32B179D75F1BD00A4E24AC312A4EA9402A1ACA5 - Submitted as: 50f6166d114a15e1fa03ae0796a24ddbe11de70f41de75cfca4dafddc2170952
- File type: script · Size: 48870 bytes
- Verdict: suspicious (41/100)
Detections (2 of 53 engines)
- Microsoft Defender: flagged
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 41/100 is the fusion of 1 weighted signal:
- Obfuscated powershell script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- zloirock.ru
- web.url.to
- groupintech.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report