MALICIOUS — 6b55cac6595b57af008abe94c141895bac19e24328c2c81fc5c01d17b8dc23e0
MALICIOUS — 6b55cac6595b57af008abe94c141895bac19e24328c2c81fc5c01d17b8dc23e0 is a script sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (74/100), attributed to the AMTB family. 3 of 51 detection engines flagged it.
Identification
- SHA-256:
6b55cac6595b57af008abe94c141895bac19e24328c2c81fc5c01d17b8dc23e0 - SHA-1:
951fb04ab4e7ef4616b65a31d4bf411db847458b - MD5:
561d1c498c59f003b324ca477796cd0a - ssdeep:
48:2FFFFFFFFF2FFFFFFFFWFFFFFFOFFFFFFFFF2FFFFFFFFWFFFFFFOFFFFFFFFF28:K - TLSH:
T17A1F12900E8EC831E364D00F0F689D0D33121582EEDEB022FB49F31A124E38720A6760 - Submitted as: 6b55cac6595b57af008abe94c141895bac19e24328c2c81fc5c01d17b8dc23e0
- File type: script · Size: 7328 bytes
- Verdict: malicious (74/100) · Family: AMTB
Detections (3 of 51 engines)
- Microsoft Defender: Trojan:BAT/Bomb!AMTB
- Emsisoft (Emergency Kit): Gen:Heur.Bat.1
- Kaspersky (KVRT): Trojan.BAT.Bomb.f
Why this verdict
The malicious score of 74/100 is the fusion of 3 weighted signals:
- Microsoft Defender flagged Trojan:BAT/Bomb!AMTB (rule
Trojan:BAT/Bomb!AMTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Heur.Bat.1 (rule
Gen:Heur.Bat.1) - engine signal, weight 0.55, confidence 0.85 - Contacted 8 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (linux)
843 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- entropy.ubuntu.com
- v10.events.data.microsoft.com
- _dosvc._tcp.local
- ntp.ubuntu.com
- 185.125.189.53:443
- 185.125.189.53
- 10.240.0.1
- 104.68.3.77
- 2.18.225.206
- 224.0.0.251
- ff02::fb
- ff02::2
- ff02::1:ff12:3456
- 91.189.91.157
- 48.211.4.16
- 255.255.255.255
- ff02::16
- 203.26.79.13
- 20.184.175.15
- ff02::1
Dropped files
- tmp_tmp.pbQD97Q3Nf -
dbffd95a26ced0aebe33b5de7bd77d68c04684ca39ed0df86328ea58df83249c
Embedded IP addresses
- 104.68.3.77
- 2.18.225.206
- 48.211.4.16
- 203.26.79.13
- 20.184.175.15
More AMTB samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report