SUSPICIOUS — 641f3fa64e9ce989a1ebddf01e0b28128b34a2804f8ab889cdebd1a7a3f1cafc
SUSPICIOUS — 641f3fa64e9ce989a1ebddf01e0b28128b34a2804f8ab889cdebd1a7a3f1cafc is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
641f3fa64e9ce989a1ebddf01e0b28128b34a2804f8ab889cdebd1a7a3f1cafc - SHA-1:
4af7f4408b28f132a088d4b0d5e43830e11343c6 - MD5:
3dafdfce50f5532138f8f0d4051ca3d7 - ssdeep:
1536:rUO4bK31DtQOREiujecX4N+qXWuE2gMUt/Tn//JFErmDFgHRwQSUiEfco5r39b9G:rUUMed4FfCOjFOWPa5i - TLSH:
T15A3AE7977C4B6DDCDC0EA0673E89A8F677035D16B95A44C9C3FAC74CB8A1890189C42B - Submitted as: 641f3fa64e9ce989a1ebddf01e0b28128b34a2804f8ab889cdebd1a7a3f1cafc
- File type: script · Size: 100911 bytes
- Verdict: suspicious (54/100)
Detections (2 of 50 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://flesler.blogspot.com, http://code.dougneiner.com, http://www.opensource.org/licenses/mit-license - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://github.com/jquery-form/form
- https://github.com/jquery-form/form#license
- http://flesler.blogspot.com
- http://code.dougneiner.com
- https://github.com/dcneiner/In-Field-Labels-jQuery-Plugin
- http://www.opensource.org/licenses/mit-license
- http://www.opensource.org/licenses/gpl-license
Embedded domains
- github.com
- e.name
- y.name
- m.name
- this.name
- t.name
- flesler.blogspot.com
- qtip2.com
- f.metadata.name
- g.top
- y.top
- h.top
- c.top
- i.top
- schemas-microsoft.com
- h.br
- k.top
- o.top
- d.top
- b.name
- f.position.top
- f.position.bottom-f.position.top
- n.top
- f.top
- e.top
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report