MALICIOUS — 71c7cbb42289fe16b17e4ad550f00bd11875ed823d0e7b1abc5453fddecc6013
MALICIOUS — 71c7cbb42289fe16b17e4ad550f00bd11875ed823d0e7b1abc5453fddecc6013 is a script sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (76/100), attributed to the Webshell family. 1 of 54 detection engines flagged it.
Identification
- SHA-256:
71c7cbb42289fe16b17e4ad550f00bd11875ed823d0e7b1abc5453fddecc6013 - SHA-1:
bbc744cf87e026ba7fc16870e2fb00c757498568 - MD5:
9bf716a8f0aa1f992bf261e3125418bf - ssdeep:
96:hOFUl8NmBFPXOXq+Bq/ulmlxTBVPMsAqNp4sbW0ZRKMJBHj6pvT8Qcijh:FSNWmq+gUmVpMsAqEs60ZRKMj478Mjh - TLSH:
T12D1D4223E344276F46E508CA7DC0C6297D61E0ED33798930E5EC8E87A87496AB4C53D6 - Submitted as: 71c7cbb42289fe16b17e4ad550f00bd11875ed823d0e7b1abc5453fddecc6013
- File type: script · Size: 6208 bytes
- Verdict: malicious (76/100) · Family: Webshell
Detections (1 of 54 engines)
- YARA: bartblaze: BB_Webshell_Generic_PHP
Why this verdict
The malicious score of 76/100 is the fusion of 3 weighted signals:
- YARA: bartblaze flagged BB_Webshell_Generic_PHP (rule
BB_Webshell_Generic_PHP) - engine signal, weight 0.70, confidence 0.70 - Obfuscated javascript script: dynamic-exec (layers: base64) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://www.vulnerability-lab.com/get_content.php?id=1657, http://data.esumsoft.com/download/POPPeeperPro.zip, http://zwx.fr/videos/POPPeeper.html - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
1073 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- desktop-hsgcbep(2)._dosvc._tcp.local
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.209
- 23.11.37.157
- 20.190.167.66
- 23.33.238.178
- 23.198.40.44
- 20.247.184.197 SG · Singapore · AS8075 Microsoft Corporation
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
- 23.33.238.100
Embedded URLs
- http://www.vulnerability-lab.com/get_content.php?id=1657
- http://data.esumsoft.com/download/POPPeeperPro.zip
- http://zwx.fr/videos/POPPeeper.html
- http://zwx.fr
- http://www.vulnerability-lab.com/show.php?user=ZwX
- http://www.vulnerability-lab.com/keys/admin@vulnerability-lab.com%280x198E9928%29.txt
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- www.vulnerability-lab.com
- data.esumsoft.com
- zwx.fr
- www.vuln-lab.com
- www.evolution-sec.com
- vulnerability-lab.com
- evolution-sec.com
- magazine.vulnerability-db.com
- twitter.com
- facebook.com
- youtube.com
Embedded IP addresses
- 20.42.179.204
- 20.184.175.19
- 48.211.4.16
- 20.42.179.192
- 20.247.184.197
- 4.230.171.124
- 20.184.175.9
- 57.155.104.224
More Webshell samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report