CLEAN — funpay-setup.cjs
CLEAN — funpay-setup.cjs is a shell sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (21/100). 0 of 53 detection engines flagged it.
Identification
- SHA-256:
6655258d3381c58783bab82c6b637e22adae0dcdee03daad1a84dea7c58563a6 - SHA-1:
18c00f0ca83ef503f4909c6b8878f890b631d3e5 - MD5:
c5bb8a11cc44dd4acb8e6028eb99ffb2 - ssdeep:
384:/BiRubfwItjrcr0v0zIJXDNWXCL5aljW6uiGE:/BiRUtowv0zIrWXq0AE - TLSH:
T1D827C7EB23294C5F4B9062052B8C903F212726E72969979063C8FCA458B3D1CFD796CD - Submitted as: funpay-setup.cjs
- File type: shell · Size: 16520 bytes
- Verdict: clean (21/100)
Detections (0 of 53 engines)
No engine flagged this sample.
Why this verdict
The clean score of 21/100 is the fusion of 1 weighted signal:
- Embedded network infrastructure: https://buytokens.duckdns.org - static signal, weight 0.35, confidence 0.60
Dynamic analysis (linux)
137 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- ntp.ubuntu.com
- 10.240.0.1
- 185.125.190.57
- 10.240.0.76
- ff02::16
- ff02::1:ff12:3456
- ff02::2
- 255.255.255.255
Embedded URLs
- https://buytokens.duckdns.org
Embedded domains
- buytokens.duckdns.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report