SUSPICIOUS — 6ee6fc892de79953ab678b447151f27578fed64fb77f618c1dc6dcd611c08b11
SUSPICIOUS — 6ee6fc892de79953ab678b447151f27578fed64fb77f618c1dc6dcd611c08b11 is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
6ee6fc892de79953ab678b447151f27578fed64fb77f618c1dc6dcd611c08b11 - SHA-1:
732c3ab4c6fdc678181280f539649f36ce5679d2 - MD5:
4d57f051ba8073a79a89c5a0c5ea2fab - ssdeep:
768:tjKMQCZOMwqqVD818IdtxFiuV4SeX8729J5ysb3q1dlQX9ylX6cdLjLdclANHl1Y:b9ZOYNJ3DiuA429jys+5K7NaXxof66 - TLSH:
T1CC3519563C59A98CEC9C45277E7DF5EA37276E1278223DCC837DCB25A0B0A908C14639 - Submitted as: 6ee6fc892de79953ab678b447151f27578fed64fb77f618c1dc6dcd611c08b11
- File type: script · Size: 60945 bytes
- Verdict: suspicious (54/100)
Detections (2 of 53 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://fancyapps.com/fancybox/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://fancyapps.com/fancybox/
- http://www.w3.org/2000/svg
Embedded domains
- fancyapps.com
- u.top
- a.top
- e.top
- t.top
- l.top-i.top
- e.body.style.top
- www.youtube.com
- img.youtube.com
- vimeo.com
- player.vimeo.com
- metacafe.com
- www.metacafe.com
- dailymotion.com
- www.dailymotion.com
- vine.co
- d.top
- n.top
- www.facebook.com
- www.w3.org
- www.pinterest.com
- twitter.com
- fresh1069fm.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report