SUSPICIOUS — 7c83cf241d34c75c75aa1d81bf333aac84089eac9caee853f50782060932cefa
SUSPICIOUS — 7c83cf241d34c75c75aa1d81bf333aac84089eac9caee853f50782060932cefa is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (65/100), attributed to the Gootloader family. 3 of 50 detection engines flagged it.
Identification
- SHA-256:
7c83cf241d34c75c75aa1d81bf333aac84089eac9caee853f50782060932cefa - SHA-1:
2716eea5a292766838a3a5d80a5488b3882abe42 - MD5:
33dd98ef82ff2dd364d2abb89dd6e528 - ssdeep:
6144:pCLfh6nicf8Z5wPTdpM4mDoz1EsnFyyyHh3zOxPnS8kVLkIVfzYAK6k1P1:pfw4mDiTFyA6TVfMAKNZ1 - TLSH:
T14446E9C33FE158588655C5BB1CCA949AAD424D2B319530E102F89F8ADECEB73347825B - Submitted as: 7c83cf241d34c75c75aa1d81bf333aac84089eac9caee853f50782060932cefa
- File type: script · Size: 295228 bytes
- Verdict: suspicious (65/100) · Family: Gootloader
Detections (3 of 50 engines)
- YARA: SophosLabs IoCs (public): SOPHOS_Gootloader_JS
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 65/100 is the fusion of 3 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - YARA: SophosLabs IoCs (public) flagged SOPHOS_Gootloader_JS (rule
SOPHOS_Gootloader_JS) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://jquery.com/, http://sizzlejs.com/, http://jquery.org/license - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://jquery.com/
- http://sizzlejs.com/
- http://jquery.org/license
- http://weblogs.java.net/blog/driscoll/archive/2009/09/08/eval-javascript-global-context
- http://jsperf.com/thor-indexof-vs-for/5
- http://www.w3.org/TR/css3-selectors/#whitespace
- http://www.w3.org/TR/CSS21/syndata.html#value-def-identifier
- http://www.w3.org/TR/selectors/#attribute-selectors
- http://www.w3.org/TR/CSS21/syndata.html#escaped-characters
- http://bugs.jquery.com/ticket/13378
- http://bugs.jquery.com/ticket/12359
- http://msdn.microsoft.com/en-us/library/ie/hh465388.aspx#attribute_section
- http://www.w3.org/TR/2011/REC-css3-selectors-20110929/#checked
- https://bugs.webkit.org/show_bug.cgi?id=136851
- https://github.com/jquery/sizzle/pull/225
- http://www.w3.org/TR/selectors/#pseudo-classes
- http://www.w3.org/TR/selectors/#lang-pseudo
- http://www.w3.org/TR/selectors/#empty-pseudo
- http://msdn.microsoft.com/en-us/library/ms536429%28VS.85%29.aspx
- http://javascript.nwbox.com/IEContentLoaded/
- https://developer.mozilla.org/en/Security/CSP
- http://www.w3.org/TR/2003/WD-DOM-Level-3-Events-20030331/ecma-script-binding.html
- https://code.google.com/p/chromium/issues/detail?id=470258
- https://bugzilla.mozilla.org/show_bug.cgi?id=687787
- http://www.w3.org/TR/DOM-Level-3-Events/#events-focusevent-event-order
Embedded domains
- jquery.com
- sizzlejs.com
- jquery.org
- weblogs.java.net
- jsperf.com
- www.w3.org
- parent.top
- bugs.jquery.com
- msdn.microsoft.com
- bugs.webkit.org
- github.com
- javascript.nwbox.com
- developer.mozilla.org
- code.google.com
- bugzilla.mozilla.org
- connect.microsoft.com
- dev.w3.org
- erik.eae.net
- web.archive.org
- blindsignals.com
- html.spec.whatwg.org
- fluidproject.org
- this.name
- elem.name
- support.microsoft.com
More Gootloader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report