MALICIOUS — 629f0f9645ae748ade2b9dc4827c38ffb6cfdbde889ad57fc25884d21fe147b6
MALICIOUS — 629f0f9645ae748ade2b9dc4827c38ffb6cfdbde889ad57fc25884d21fe147b6 is a script sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (70/100), attributed to the Base64 family. 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
629f0f9645ae748ade2b9dc4827c38ffb6cfdbde889ad57fc25884d21fe147b6 - SHA-1:
1f29c5f18369b13f2daae8edfd5b7275cddd0b3a - MD5:
90c5a14b34af3c0908d33400c2372ff5 - ssdeep:
96:hT6T/vXhDGR8jyhwjkByLl7BB4kN8cV/yD1TRA3nims7uT5Zh34:hqvXhjyhwggul1T23ps7uTbho - TLSH:
T1781D9D095D71BFA60C50AF21465F36CAC1A161648002B0D0FAD8907DEE7AFB53DB5BE2 - Submitted as: 629f0f9645ae748ade2b9dc4827c38ffb6cfdbde889ad57fc25884d21fe147b6
- File type: script · Size: 6297 bytes
- Verdict: malicious (70/100) · Family: Base64
Detections (4 of 53 engines)
- capa (capabilities): capability:execution/powershell
- YARA: MalwareAnalyser community pack: TL_Base64_EncodedCommand
- Microsoft Defender: Trojan:PowerShell/Rozena.NJA!MTB
- Kaspersky (KVRT): HEUR:Trojan.PowerShell.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 70/100 is the fusion of 3 weighted signals:
- Obfuscated powershell script: shellcode-injection (layers: powershell-encodedcommand+base64) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - YARA: MalwareAnalyser community pack flagged TL_Base64_EncodedCommand (rule
TL_Base64_EncodedCommand) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
File paths
- C:\\Windows\\syswow64\\WindowsPowerShell\\v1.0\\powershell.exe\
More Base64 samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report