CLEAN — 7735d9a68d48c212c902dfcce2f110c0c35635a1a808597bcb4600697d4bb2d7
CLEAN — 7735d9a68d48c212c902dfcce2f110c0c35635a1a808597bcb4600697d4bb2d7 is a shell sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (21/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
7735d9a68d48c212c902dfcce2f110c0c35635a1a808597bcb4600697d4bb2d7 - SHA-1:
ea1e625bf6ebf25076fe775767fa95d3028b99ef - MD5:
45a2b33f6e4e150ce995e756bef8250c - ssdeep:
1536:h0jB6WZgUjTD9Ty8P85K70zRzEoDuxB2pHjKBH8ngLAMj:4B6WvjTD9Ty8P84Yzb6xB21080j - TLSH:
T14A36839B3ADF094E8244D1B1298D59DAFD110D26710338F802B4E78BEDCDB6B6438A57 - Submitted as: 7735d9a68d48c212c902dfcce2f110c0c35635a1a808597bcb4600697d4bb2d7
- File type: shell · Size: 66129 bytes
- Verdict: clean (21/100)
Detections (2 of 53 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The clean score of 21/100 is the fusion of 1 weighted signal:
- Embedded network infrastructure: http://locutus.io/php/number_format/, http://locutus.io/php/empty/, http://stackoverflow.com/a/873856/1489528 - static signal, weight 0.35, confidence 0.60
Dynamic analysis (linux)
819 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- 250.255.255.239.in-addr.arpa
- _dosvc._tcp.local
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- ntp.ubuntu.com
- desktop-hsgcbep
- desktop-hsgcbep(2)._dosvc._tcp.local
- 224.0.0.251
- ff02::fb
- ff02::1:3
- 224.0.0.252
- 10.240.0.1
- 239.255.255.250
- ff02::1:ff12:3456
- ff02::16
- 10.240.0.255
- ff02::2
- 224.0.0.22
- 255.255.255.255
- ff02::1:ff4c:1d1d
Embedded URLs
- http://locutus.io/php/number_format/
- http://locutus.io/php/empty/
- http://stackoverflow.com/a/873856/1489528
- https://ipapi.co/jsonp
- https://geo.wpforms.com/v3/geolocate/json
Embedded domains
- element.name
- offset.top
- locutus.io
- stackoverflow.com
- ipapi.co
- geo.wpforms.com
- start360up.com
Embedded IP addresses
- 20.42.73.25
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report