SUSPICIOUS — 7a95e8725475d849b83b9702043f61ddd004e807d165c38065ad34631af59cae
SUSPICIOUS — 7a95e8725475d849b83b9702043f61ddd004e807d165c38065ad34631af59cae is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 0 of 54 detection engines flagged it.
Identification
- SHA-256:
7a95e8725475d849b83b9702043f61ddd004e807d165c38065ad34631af59cae - SHA-1:
4ff9699c177fdb92c85d1d666bed9034494be212 - MD5:
eb7df3a7834544a0171e99a0834c9c11 - ssdeep:
384:lb4WUq4+ygBSvk/8uRsMHaK7EBuyEjXpqanMwOs:lRUq4mKs8uRHHlbjus - TLSH:
T17B2C741E37C4B5EA841098326E4E44886DE0DD0BFE7554C5C98CCA846ECEA67B4A4CF7 - Submitted as: 7a95e8725475d849b83b9702043f61ddd004e807d165c38065ad34631af59cae
- File type: script · Size: 25988 bytes
- Verdict: suspicious (54/100)
Detections (0 of 54 engines)
No engine flagged this sample.
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://cleverjump.org/counter.js, https://semalt.com, https://semalt.com/?s= - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
1185 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.209
- 162.159.142.9 US · San Francisco · AS13335 Cloudflare, Inc.
- 172.217.25.206
- 20.42.179.204 US · Moses Lake · AS8075 Microsoft Corporation
- 150.171.22.17
- 23.33.238.178
- 192.168.122.108
- 52.110.12.52 AU · Sydney · AS8075 Microsoft Corporation
- 4.230.171.124 KR · Seoul · AS8075 Microsoft Corporation
- 40.84.85.40 US · Boydton · AS8075 Microsoft Corporation
- 20.190.167.19
- 23.33.238.114
Dropped files
- 13a5cad51467fbabcda0259d9e251f6b0fa0f5ceef533557d5f3d6948c954743 -
13a5cad51467fbabcda0259d9e251f6b0fa0f5ceef533557d5f3d6948c954743
Embedded URLs
- https://cleverjump.org/counter.js
- https://semalt.com
- https://semalt.com/?s=
- https://semalt.com/popups/popup_wow.php?lang=en
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- kickvox.com
- wallselectrical.ca
- kukolki.com.ua
- podavach.store
- remeshok.com.ua
- www.tarduosgb.com
- mir-igr.com.ua
- 168freegame.com
- sermons-online.org
- starbeautycosmetic.com.au
- priceclub.com.ua
- autobahnfahrschule.com
- www.optimedialabs.ca
- jhdesentupidora.com.br
- monami.kiev.ua
- www.hempstaff.com
- suppertownnote.com
- kardamon.com.ua
- certifiedautorepair.us
- solzi.com.ua
- www.iqmatics.com
- nameversion.com
- com-furniture.com
- rmsmultimidia.com
- buybikeshq.com
Embedded IP addresses
- 57.155.101.212
- 57.154.63.210
- 40.84.97.4
- 162.159.142.9
- 20.42.179.204
- 52.110.12.52
- 4.230.171.124
- 40.84.85.40
- 74.179.77.164
- 135.232.92.137
- 20.184.175.9
- 92.223.78.30
- 72.153.5.130
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report