CLEAN — 7a049a703e778232149e51e77a6b63b3cd70a977610315e19f37dd61900b322a
CLEAN — 7a049a703e778232149e51e77a6b63b3cd70a977610315e19f37dd61900b322a is a script sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (21/100). 0 of 53 detection engines flagged it.
Identification
- SHA-256:
7a049a703e778232149e51e77a6b63b3cd70a977610315e19f37dd61900b322a - SHA-1:
19a60b30100c7fda87a4c99e8693542a4f7c1c8e - MD5:
fb23c7fb887af2e125a48e4b17a32ccc - ssdeep:
96:m5Ev4FfbFSCGG/iSrXZlCytT81FA9QERVSLj:yEEfbFSCGciSrDCytT81FAVRVSLj - TLSH:
T1C21ABDB69B317EEFAB8625C5690D1CAF0A0360C3B400AA69DA44A9C55C63C991F1CC5C - Submitted as: 7a049a703e778232149e51e77a6b63b3cd70a977610315e19f37dd61900b322a
- File type: script · Size: 4439 bytes
- Verdict: clean (21/100)
Detections (0 of 53 engines)
No engine flagged this sample.
Why this verdict
The clean score of 21/100 is the fusion of 1 weighted signal:
- Embedded network infrastructure: http://rediskina.com/f/gstats - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
1141 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- motd.ubuntu.com
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- desktop-hsgcbep
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded URLs
- http://rediskina.com/f/gstats
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787904952&P2=404&P3=2&P4=KvcsQS%2bir%2fqG92affss4zDHHEsKokxo9wdR%2bZyFat36RAWJ1YzjYN50ZY2QX17SPhoo1YFVjO1Rf1ANsUZAKjw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787905024&P2=404&P3=2&P4=e0iIQINtWwsNBfthgehqJcD6sNxKYKbc5WAJCRmglVLxPDRGstCSuOGJ0T78GytI1W9x%2bAEQGj%2b6zaGAu4YGvg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5?P1=1787301741&P2=404&P3=2&P4=lKm%2bIq%2fhx7NG5e7qf4k%2fKaDlT0nwz6vmMmstsRlkzcCj95zru%2f4eqmpv7PMN7gFcH17XLADksoZ0Im5smWVSCA%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/b56480f9-8215-4de7-ba7e-8e690088d21d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/b56480f9-8215-4de7-ba7e-8e690088d21d?P1=1787301300&P2=404&P3=2&P4=S%2bGLUG7iUCMLekfoUvB878zZrgtrGflbqOCD2N5INZFW8lZMV2PrHzMvv8gSUx%2bu4Z9Jjp0F%2blaR7QzCEQP3AA%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- rediskina.com
Embedded IP addresses
- 34.244.58.147
- 135.233.95.144
- 20.165.94.46
- 135.232.92.34
- 52.110.12.10
- 40.84.97.4
- 4.230.171.124
- 203.26.79.13
- 4.144.132.114
- 135.232.92.137
- 20.42.73.25
- 20.112.250.133
- 52.123.129.14
- 40.99.134.18
- 92.223.78.30
- 51.116.246.106
- 20.184.175.6
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report