SUSPICIOUS — 129205357-lbx__pt_br.js
SUSPICIOUS — 129205357-lbx__pt_br.js is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 0 of 53 detection engines flagged it.
Identification
- SHA-256:
7957d117a68d99b69544472996d943f960aac92be9b4e3b0b5fdf2eb03af4eb1 - SHA-1:
64f82417b2aef015447d371d709bd1c29aef4827 - MD5:
97747b8237eeaf4fb5b318924b94f176 - ssdeep:
3072:ZkH5AesSF4RqQiKiqf9763c5wauXc4AtXjldCrlsiEmfiLLvL4p3/60klP:ZkZG8W5JxwStXUUvL4CN - TLSH:
T11C485FDE3986BEDEDC4E70AE7E4CA893B3039E14B65590E083BDD32594E18D03D68815 - Submitted as: 129205357-lbx__pt_br.js
- File type: script · Size: 361544 bytes
- Verdict: suspicious (54/100)
Detections (0 of 53 engines)
No engine flagged this sample.
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated powershell script: dynamic-exec, defense-evasion (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://flickr.com/photos/, 2.0.0.11 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://photos.google.com/lightbox/photoid
- http://flickr.com/photos/
- http://picasaweb.google.com/
- http://google.com/profiles/media/container
- http://google.com/profiles/media/provider
- http://www.google.com/intl/
Embedded domains
- photos.google.com
- ae.prototype.name
- this.be
- a.be
- q.fi
- this.ga
- e.ga
- this.hk
- q.su
- this.constructor.tw
- this.gg
- this.se
- q.se
- a.ly
- q.ca
- q.sg
- q.ua
- this.ua
- h.name
- q.ly
- c.ai
- this.ai
- q.jp
- q.ai
- this.jp
Embedded IP addresses
- 2.0.0.11
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report