SUSPICIOUS — docsify.min.js
SUSPICIOUS — docsify.min.js is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (41/100). 0 of 50 detection engines flagged it.
Identification
- SHA-256:
769c6eac503ed151495606a6d060b1b4cd217200b0b046eec1ed6e0fe2d841f0 - SHA-1:
d6bed0cf5b6a0def2ac35b240f0d53fee7b5aa90 - MD5:
06171a6c8bc57a85c9c57c48d588db19 - ssdeep:
768:a9F9II9gEGCQM7xI3WyIpJW/zG0y7vj45LC9DRBDx8a8n7VWiU:0F9II9f7xgW5pJW/6067UeFLxynpWJ - TLSH:
T10033C96AB94D7F9CCC0E540B2EC8B8FB7713AD217561A0D5E36CDB9464E48D01CAC81A - Submitted as: docsify.min.js
- File type: script · Size: 51064 bytes
- Verdict: suspicious (41/100)
Detections (0 of 50 engines)
No engine flagged this sample.
Why this verdict
The suspicious score of 41/100 is the fusion of 1 weighted signal:
- Obfuscated powershell script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://github.com/
- https://assets-cdn.github.com/images/icons/emoji/
- https://github.com/chjj/marked
Embedded domains
- github.com
- e.name
- assets-cdn.github.com
- le.name
- p.link
- p.br
- a.renderer.link
- a.renderer.br
- this.renderer.link
- r.prototype.br
- r.prototype.link
- a.link
- e.link
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report