MALICIOUS — 6f63618f670d3a5636fed5677ebb1aa59832bcd7d63e51aacfec5ebd949dc51c
MALICIOUS — 6f63618f670d3a5636fed5677ebb1aa59832bcd7d63e51aacfec5ebd949dc51c is a script sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (77/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6f63618f670d3a5636fed5677ebb1aa59832bcd7d63e51aacfec5ebd949dc51c - SHA-1:
abd8e693834913f4f0f5bbcf6607774d958aca98 - MD5:
9e0f15e593e3760bc46c536d25870fe4 - ssdeep:
96:l/1X1kq607L3O3f9VFQiqef7L3h+rf9VrQl:lp6m3gueH3w7W - TLSH:
T1F617796E92D439B702CCFD0314D3C64EE253128A3CEA12CB5D655A32A008EECF497987 - Submitted as: 6f63618f670d3a5636fed5677ebb1aa59832bcd7d63e51aacfec5ebd949dc51c
- File type: script · Size: 3317 bytes
- Verdict: malicious (77/100)
Detections (2 of 53 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- Microsoft Defender: flagged
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 77/100 is the fusion of 3 weighted signals:
- Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - Obfuscated vbscript script: shellcode-injection (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - inject code into another process (rule
inject code into another process) - capa signal, weight 0.12, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report