SUSPICIOUS — jquery.favicon.js
SUSPICIOUS — jquery.favicon.js is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 0 of 53 detection engines flagged it.
Identification
- SHA-256:
74dde689597c84df5e4adc35bc7145ca66a6d18f8787006701b389af3a813b65 - SHA-1:
b91d275ca867fa5ed76d587d1b48124dbb02ba79 - MD5:
da96e094cdbe864f514021c3c1268ca7 - ssdeep:
48:3Tgxb67IhASYs5w9vRwxf3p1adk5/5NTuxNG6XhRJw4KmOF85sdEI+B6sdB:30+UVo5R0yk5/5UxNG8RO4YG5qt+dB - TLSH:
T13B1B0E44E27A78EF0B1FC5BEA4E4452EA4470EE630C171D5AEC86B874458F82E01657F - Submitted as: jquery.favicon.js
- File type: script · Size: 4985 bytes
- Verdict: suspicious (54/100)
Detections (0 of 53 engines)
No engine flagged this sample.
Why this verdict
The suspicious score of 54/100 is the fusion of 4 weighted signals:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 28 external host(s) at runtime (27 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://hellowebapps.com/products/jquery-favicon/, http://www.opensource.org/licenses/mit-license.php, http://www.gnu.org/licenses/gpl.html - static signal, weight 0.35, confidence 0.60
- Extracted generic config (2 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
345 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
Embedded URLs
- http://hellowebapps.com/products/jquery-favicon/
- http://www.opensource.org/licenses/mit-license.php
- http://www.gnu.org/licenses/gpl.html
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787729814&P2=404&P3=2&P4=aYpbRtmg5Lpkv%2fYOC1GP9c%2bsWXjlGKS7zBFvh297CgWkkEhVntOCcWKscKIW9z6T5mZWGnqMzpaLizkN%2burYHw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787729865&P2=404&P3=2&P4=XU1YN%2f39FhTXyB%2fXFqKHLi5aRnavMOkQkp3irIToTkbNl4WSgaWEXPsXNcrzOJsbtf6N6M%2b7HPWUfk2u4jPFbw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5?P1=1787126537&P2=404&P3=2&P4=nu2%2bHzl1FdqodHtIc3vmC8XA66CPaEIF3290tguGMAY2VXiIApbwaZEuX%2bYnPKV6NRCrfR%2bduqEU9fR8MQI2hw%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/b56480f9-8215-4de7-ba7e-8e690088d21d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/b56480f9-8215-4de7-ba7e-8e690088d21d?P1=1787126158&P2=404&P3=2&P4=dgJTY6wIVHH2nQnGQMx2wZqo5F7Oje%2bofj7IqaXPzK1Kpm5cZFO4rYBJjnHeWFohcIJc5VGn%2fyZK%2bbUUhFV3rg%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- hellowebapps.com
- www.opensource.org
- www.gnu.org
Embedded IP addresses
- 203.26.79.13
- 142.250.195.142
- 104.208.16.94
- 52.110.12.14
- 52.230.60.54
- 135.233.95.80
- 52.110.12.44
- 4.230.171.124
- 85.210.193.152
- 40.84.85.40
- 74.179.77.204
- 4.150.223.99
- 74.178.240.51
- 92.223.78.30
- 52.123.128.14
- 20.236.44.162
- 40.99.133.242
- 51.104.15.253
- 4.150.223.104
- 51.105.71.137
- 135.233.45.223
- 52.123.252.232
- 52.148.114.188
- 72.145.35.99
- 48.200.63.27
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report