SUSPICIOUS — codeMirror.bundle.min.js
SUSPICIOUS — codeMirror.bundle.min.js is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (41/100). 0 of 50 detection engines flagged it.
Identification
- SHA-256:
7b5277fff495c8fc86f70c16bec5efaaf10fa40a2a7dd2698cb1736bf53c5b4f - SHA-1:
e8a2af1c8cda2a16e16f70b58ceb52bf0aa36faa - MD5:
4cecc23ec5e5a1d9c9e02aa46dd85882 - ssdeep:
1536:0IM9OEsKWeVBTkt5tLKi1ECjCYrYX7jcJWkTonQcjNmx3l6MoeyaXKI3c5XMWsXZ:zM9O/xPji7j4TWjNW96dXMWwfxlY8 - TLSH:
T1E641D5BB388D3ADDCC0F945A3D5CB8AB7757DA69B9A040C4A36CD39CB4B0CA01424C65 - Submitted as: codeMirror.bundle.min.js
- File type: script · Size: 190628 bytes
- Verdict: suspicious (41/100)
Detections (0 of 50 engines)
No engine flagged this sample.
Why this verdict
The suspicious score of 41/100 is the fusion of 1 weighted signal:
- Obfuscated javascript script: dynamic-exec, defense-evasion (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- n.ch
- t.ch
- this.ch
- e.ch-t.ch
- e.ch
- this.to
- t.from.ch
- t.to.ch
- t.to
- o.to
- h.to
- d.to
- g.to
- n.to
- r.to
- i.to
- u.to
- i.from.ch-i.to.ch
- r.text.length-o.from.ch
- r.text.length-o.to.ch
- e.name
- t.name
- r.name
- f.to
- w.to
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report