MALICIOUS — 739004055d419b683ad67afcff860440201893afb1a854eb8784b0c2e59b5698
MALICIOUS — 739004055d419b683ad67afcff860440201893afb1a854eb8784b0c2e59b5698 is a script sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100), attributed to the Adoberd28 family. 4 of 50 detection engines flagged it.
Identification
- SHA-256:
739004055d419b683ad67afcff860440201893afb1a854eb8784b0c2e59b5698 - SHA-1:
678a5dd6d0026a5da26379792ef2073a7cd9e43a - MD5:
1dc083457be591cf90c788f9990ddbd9 - ssdeep:
192:EvS1CO0kiyBIoGNeUO8+OLbOzOKaOaG8aYaa/PrdQussL7Cm6jsD7ScQ61Rq/iqL:EvdNXZ+CbSA+8aYaa/PrLs91 - TLSH:
T17224FA7D837D5A7FC5B41F65EA54B9EE380738C06B11E531DA22BE4B59C3CA8844C221 - Submitted as: 739004055d419b683ad67afcff860440201893afb1a854eb8784b0c2e59b5698
- File type: script · Size: 12435 bytes
- Verdict: malicious (93/100) · Family: Adoberd28
Detections (4 of 50 engines)
- ClamAV (daily): {HEX}php.magento.adoberd28.584.UNOFFICIAL
- Microsoft Defender: Trojan:HTML/OLookPhish.H!MTB
- Emsisoft (Emergency Kit): Generic.HTML.Phishing.L.1F4BF85E
- Kaspersky (KVRT): HEUR:Hoax.HTML.Phish.gen
Why this verdict
The malicious score of 93/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged {HEX}php.magento.adoberd28.584.UNOFFICIAL (rule
{HEX}php.magento.adoberd28.584.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://gmail.com/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://gmail.com/
Embedded domains
- gmail.com
More Adoberd28 samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report