SUSPICIOUS — 5c4c94ccf9bdc9cb7f4b21896afa5e29cc83d1144cf6aab3da1fb56db2351e33
SUSPICIOUS — 5c4c94ccf9bdc9cb7f4b21896afa5e29cc83d1144cf6aab3da1fb56db2351e33 is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (41/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
5c4c94ccf9bdc9cb7f4b21896afa5e29cc83d1144cf6aab3da1fb56db2351e33 - SHA-1:
190f0ddd2f77777841e4133f206a6643d2123fd5 - MD5:
96139b09c5f2948a3f4d51b3761aca78 - ssdeep:
384:XWxb9XXAhOfMSelTARgzoSC0Z4eAchzD/DM5Ksdu:8b9uTARgz5C0ZVDLydu - TLSH:
T1BA28F967F9AB3BB1455FC8177D45F80B1648DB6621A80468838A6E33EA04464FD2327F - Submitted as: 5c4c94ccf9bdc9cb7f4b21896afa5e29cc83d1144cf6aab3da1fb56db2351e33
- File type: script · Size: 16714 bytes
- Verdict: suspicious (41/100)
Detections (2 of 50 engines)
- Microsoft Defender: flagged
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 41/100 is the fusion of 1 weighted signal:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- bedworthparkguesthouse.co.za
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report