SUSPICIOUS — 6f77be7a27a3ea6993b8defa7f61f442aa1284d63924d4cdf6255e0b102fd0ec
SUSPICIOUS — 6f77be7a27a3ea6993b8defa7f61f442aa1284d63924d4cdf6255e0b102fd0ec is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (41/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6f77be7a27a3ea6993b8defa7f61f442aa1284d63924d4cdf6255e0b102fd0ec - SHA-1:
e15e0dfb76d8b4365904e5ffef1579cd084f8ce3 - MD5:
a82d51a18dce592ea2159299566359cc - ssdeep:
3072:dIlbxUpj1WvP6IoPap1lNIgByc84nmDXUnbWYKScWoCzgv:dIlbxUpj1WvP6IoPardzmOjXiCzc - TLSH:
T1BB44190F359EFF9E9C88A2DB384CED6AF5639401BDA1C4D4C1FCC78EAD248502598865 - Submitted as: 6f77be7a27a3ea6993b8defa7f61f442aa1284d63924d4cdf6255e0b102fd0ec
- File type: script · Size: 254378 bytes
- Verdict: suspicious (41/100)
Detections (2 of 50 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 41/100 is the fusion of 1 weighted signal:
- Obfuscated javascript script: dynamic-exec, defense-evasion (layers: char-code) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75
Dynamic analysis (windows)
1085 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- searchapp.bundleassets.example
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- desktop-hsgcbep
- none
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- none.local
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- 250.255.255.239.in-addr.arpa
- NONE
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
Embedded URLs
- http://www.w3.org/2000/svg
- http://www.w3.org/1999/xlink
- http://www.w3.org/XML/1998/namespace
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice/files/a953f41c-6a2b-4053-a8e2-073df6f434a3/pieceshash?cacheHostOrigin=msedge.f.dl.delivery.mp.microsoft.com
Embedded domains
- www.w3.org
- t.style.top
- r.style.top
- s.to
- this.sh
- this.or.sh
- this.ir
- e.ir
- t.sh
- this.data.sh
- this.it
- t.fr
- e.sh
- t.ml
- this.co
- r.co
- r.ml
- h.co
- h.ml
- i.co
- a.top
- this.name
- t.name
- r.name
- elem.data.sh
Embedded IP addresses
- 20.184.175.12
- 74.179.77.204
- 92.223.78.30
- 40.84.85.40
- 85.210.193.152
- 57.155.104.224
- 20.184.175.13
- 20.231.239.246
- 72.154.7.102
- 4.230.171.124
- 203.26.79.13
- 20.112.250.133
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report