SUSPICIOUS — 80b504e3f36749a8d92abfff03692065ef766e49109a95fd2461d607a2c9bae8
SUSPICIOUS — 80b504e3f36749a8d92abfff03692065ef766e49109a95fd2461d607a2c9bae8 is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
80b504e3f36749a8d92abfff03692065ef766e49109a95fd2461d607a2c9bae8 - SHA-1:
2bc1725eba2d873e43fc3791450f65466ba41b66 - MD5:
4507358c01ff5cb72e455723cbd24d4a - ssdeep:
96:l9frrncMia+5rLHeCbMmXygFtFMssTaajfNBvDEmppC2kclS+2fP68ku:lhrTcda+5rLHDbM+yGFnsTaajfNBDpsl - TLSH:
T1FB1B85D66CCA5EECC84EA1577F4FB4CB3F4A991276528484828D974928B68C13C1C636 - Submitted as: 80b504e3f36749a8d92abfff03692065ef766e49109a95fd2461d607a2c9bae8
- File type: script · Size: 5203 bytes
- Verdict: suspicious (54/100)
Detections (2 of 53 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://brm.io/jquery-match-height/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
1223 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- desktop-hsgcbep
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787912498&P2=404&P3=2&P4=ALV%2bYbInZsjSog%2fwGHSpQTh4trxUmt6Hca6MxrqU314aN%2biXCiEPJxCvj0tNl04hTYF9AfpSCt%2fcOUwmpN%2fyWw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/51d86688-616b-47e3-abeb-3df16a1583c5?P1=1787912541&P2=404&P3=2&P4=QB6dRx1Uz8%2fS8zIIRu53qWR9wxgs9hYCiRk%2b4MnkWpgFdXvXYEZDChNpQUIw%2b7Ja1h1u4evyebIk1yVP5Jj7Og%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded URLs
- http://brm.io/jquery-match-height/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787912498&P2=404&P3=2&P4=ALV%2bYbInZsjSog%2fwGHSpQTh4trxUmt6Hca6MxrqU314aN%2biXCiEPJxCvj0tNl04hTYF9AfpSCt%2fcOUwmpN%2fyWw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/51d86688-616b-47e3-abeb-3df16a1583c5?P1=1787912541&P2=404&P3=2&P4=QB6dRx1Uz8%2fS8zIIRu53qWR9wxgs9hYCiRk%2b4MnkWpgFdXvXYEZDChNpQUIw%2b7Ja1h1u4evyebIk1yVP5Jj7Og%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- brm.io
- edenroc.biz
Embedded IP addresses
- 57.155.101.212
- 92.223.78.30
- 20.42.73.28
- 52.123.252.193
- 20.247.185.124
- 162.159.142.9
- 52.110.12.15
- 4.230.171.124
- 135.232.92.97
- 20.165.94.63
- 51.132.193.105
- 52.123.128.14
- 40.103.64.242
- 135.232.92.34
- 203.26.79.13
- 48.211.4.16
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report