SUSPICIOUS — chargebee.js
SUSPICIOUS — chargebee.js is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (59/100). 0 of 50 detection engines flagged it.
Identification
- SHA-256:
548e3fb4e441be26774bfec27beb6e26064740758261f75574a326e23c8dcbc6 - SHA-1:
7149403abfdbcdedd3a226a715a586062e00e460 - MD5:
124e3d84172fed05b9cfcaffc9711aa6 - ssdeep:
12288:RNoUpWUqCK8ZIIl/c4xyyr/41Gnnx+nmmx6q57kBvu9fNpz:b3pvIIKq48x+ngq57kxu9fNpz - TLSH:
T1D1533C6738493ECDCC0D969BBC887C777B579A79E9B090C4C2A9C704ACA4CB07C58859 - Submitted as: chargebee.js
- File type: script · Size: 1041291 bytes
- Verdict: suspicious (59/100)
Detections (0 of 50 engines)
No engine flagged this sample.
Why this verdict
The suspicious score of 59/100 is the fusion of 4 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://js.chargebee.com, https://js.chargebee.com/components/v1/payment/dialog.html, https://js.chargebee.com/components/v1/payment/component.html - static signal, weight 0.35, confidence 0.60
- Contacted 2 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (11 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
945 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- ntp.ubuntu.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 250.255.255.239.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- desktop-hsgcbep
- ff02::1:3
- 224.0.0.252
- 10.240.0.1
- 224.0.0.251
- ff02::fb
- ff02::16
- 10.240.0.255
- 224.0.0.22
- 185.125.190.56
- ff02::1:ff4c:1d1d
- ff02::1:ff12:3456
- ff02::2
- 239.255.255.250
Dropped files
- tmp_tmp.3jZAA5gJyS -
1438ec2160b44288e9ae2050a093edf2d066c1ea6dc044bf59191e13b3ff55a6
Embedded URLs
- https://js.chargebee.com
- https://js.chargebee.com/components/v1/payment/dialog.html
- https://js.chargebee.com/components/v1/payment/component.html
- https://js.chargebee.com/components/v1/payment/button.html
- https://js.chargebee.com/assets/cbjs-2026.08.03-09.32/v2
- https://js.chargebee.com/atomicpricing/pricify.js
- https://app.retention.chargebee.com/assets/webpack/retention.js
- https://b28572495da64a688fcaf79ded696e79@sentry.io/1454985
- https://npms.io/search?q=ponyfill
- https://reactjs.org/docs/error-decoder.html?invariant=
- http://www.w3.org/1999/xlink
- http://www.w3.org/XML/1998/namespace
- http://www.w3.org/2000/svg
- http://www.w3.org/1998/Math/MathML
- http://www.w3.org/1999/xhtml
- https://js.chargebee.com/v2/chargebee.js
- https://radix-ui.com/primitives/docs/components/alert-dialog
- https://gocardless-buttons.s3.amazonaws.com/v2/en/pay-with-gc-small@2x.png
- https://d2jxbtsa1l6d79.cloudfront.net/static/app-static-assets/cdn-app-6.1.0_v4/images/button/cn-spinner-black.svg
- https://www.chargebee.com/checkout-portal-docs/api-checkout.html#opening-chargebee-checkout
Embedded domains
- s.name
- e.name
- t.site
- e.site
- chargebee.com
- js.chargebee.com
- chargebeestaticv2.com
- app.retention.chargebee.com
- localcb.in
- devcb.in
- devcbportal.in
- stagingcb.com
- stagingcbportal.com
- predev.in
- predevportal.in
- portal.in
- window.constructor.name
- w.name
- t.name
- g.m.fr
- g.m.de
- g.m.it
- g.m.es
- a.name
- this.name
Embedded IP addresses
- 1.152.64.76
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report