SUSPICIOUS — 7e0ee47c764f1b5d3feee92d114ea9ba2d7c39de4e7f6d0633324a84c7be372a
SUSPICIOUS — 7e0ee47c764f1b5d3feee92d114ea9ba2d7c39de4e7f6d0633324a84c7be372a is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (41/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
7e0ee47c764f1b5d3feee92d114ea9ba2d7c39de4e7f6d0633324a84c7be372a - SHA-1:
1a6ec23dfed0703686a64dfbdb5d2b99e5c6aa51 - MD5:
425c06bae0a08e4f9bf2cc41109c0810 - ssdeep:
192:JrprDNvD66fPP/+I6OP1fQP0OIr96DB6MHXcwr1RIps2PzfPku:JrprxG6fPP3P1fQMOIsDsMMtsBu - TLSH:
T1A725B7877C881EACCC6E5D077EC998072B66EB197353A5C8527DD7112CB0CF1A81852E - Submitted as: 7e0ee47c764f1b5d3feee92d114ea9ba2d7c39de4e7f6d0633324a84c7be372a
- File type: script · Size: 13019 bytes
- Verdict: suspicious (41/100)
Detections (2 of 53 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 41/100 is the fusion of 1 weighted signal:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75
Dynamic analysis (windows)
1305 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- desktop-hsgcbep
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787876195&P2=404&P3=2&P4=kSzdtcm9RWG6Lm3Xc1gWNjztBIdEToIJY4QvWpV9KqtaAqAnnC0VjBX0r9kSCUBswn9gh4K3IZU7n47%2f3uUAGw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787876238&P2=404&P3=2&P4=eV2FsHHegOzbnV2lXupA9Isuayo9OG7LBxXU9ueyBUxT90TKMoVtwyu4%2bXQ%2bnd47yuLQ7Omb2Z4S1BKy585IqQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- df9bb8e7d6de5926e49147d3962cede0ade9393aa562b255939c34b7a8b4a574 -
df9bb8e7d6de5926e49147d3962cede0ade9393aa562b255939c34b7a8b4a574
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787876195&P2=404&P3=2&P4=kSzdtcm9RWG6Lm3Xc1gWNjztBIdEToIJY4QvWpV9KqtaAqAnnC0VjBX0r9kSCUBswn9gh4K3IZU7n47%2f3uUAGw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787876238&P2=404&P3=2&P4=eV2FsHHegOzbnV2lXupA9Isuayo9OG7LBxXU9ueyBUxT90TKMoVtwyu4%2bXQ%2bnd47yuLQ7Omb2Z4S1BKy585IqQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5?P1=1787272862&P2=404&P3=2&P4=LOQ2eGKgZOpy9lbvPGw4Dh%2bs9qIx6QuMOLSwFX0g8S9vhB2TNnP5H6JON%2bmXEAug7LPut5h5PdbgwQKUvr3UKg%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/b56480f9-8215-4de7-ba7e-8e690088d21d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/b56480f9-8215-4de7-ba7e-8e690088d21d?P1=1787272484&P2=404&P3=2&P4=ewA120y0l0FQ6sp5eHWeQrwANlPkyOy8pOGfSSF%2bzjp5x46lQFIaIitejpT7w5ehMPbuoum4Ut2WljZ0nkdbsA%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- jquery.org
- joaoviudescarrasco.com.br
Embedded IP addresses
- 104.208.16.94
- 52.123.252.227
- 52.110.12.48
- 52.110.12.11
- 4.247.188.233
- 4.230.171.124
- 20.247.185.124
- 20.42.73.25
- 20.76.201.171
- 52.123.128.14
- 52.168.117.174
- 92.223.78.30
- 74.178.76.128
- 74.179.71.159
- 203.26.79.13
- 52.123.252.197
- 172.170.180.133
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report