SUSPICIOUS — 7abd731014ccdb0ece25927908f0c0a4e1efd2d2f186c294042db0fb7ad367fa
SUSPICIOUS — 7abd731014ccdb0ece25927908f0c0a4e1efd2d2f186c294042db0fb7ad367fa is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (41/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
7abd731014ccdb0ece25927908f0c0a4e1efd2d2f186c294042db0fb7ad367fa - SHA-1:
01fe94ead2265538eb775424875522726b3e82e5 - MD5:
6624932bba2606c98884967362644e3f - ssdeep:
1536:muuLio3ZG/5+2Rzc4bx60BWPth93AFWgmwfuOOMxE4FMp/BE5PTiYqMo+z08ocSI:CzgmwfobSzqb8IBPK4k7R - TLSH:
T1363BF7A3BD8E6DCDDC0D945F3E88A87B77179E28F5E294C5D25CCA04A8F1CE02858458 - Submitted as: 7abd731014ccdb0ece25927908f0c0a4e1efd2d2f186c294042db0fb7ad367fa
- File type: script · Size: 104381 bytes
- Verdict: suspicious (41/100)
Detections (2 of 50 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 41/100 is the fusion of 1 weighted signal:
- Obfuscated javascript script: dynamic-exec, defense-evasion (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.w3.org/1999/xhtml
Embedded domains
- i.top
- t.name
- t.top
- this.name
- f.top
- t.top-s.top
- i.br
- i.ir
- t.ir
- n.top
- e.cn
- w.cn
- x.cn
- www.w3.org
- e.ir
- e.be
- microhub.analogcloudtech.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report