SUSPICIOUS — 8340315322c85136a8d81fc2a0abc415918536c6add633e047bcb00d5e392b2c
SUSPICIOUS — 8340315322c85136a8d81fc2a0abc415918536c6add633e047bcb00d5e392b2c is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
8340315322c85136a8d81fc2a0abc415918536c6add633e047bcb00d5e392b2c - SHA-1:
f1992f098e1deead0b6eae37b4c49d2daa8d2eee - MD5:
fa339deadc056cecb4478367b27addb1 - ssdeep:
384:8uMSX9vEqkTVScdV/vWxcHsiW58furhDGXvhHQfww/Xc2S8mFkF50NsMu:iScPy+hkLqkhMu - TLSH:
T1D12BFB9BBE4F7E9CC81E856B1D8CBA167317AA17B55750CD41FDC789ACB08F0085802A - Submitted as: 8340315322c85136a8d81fc2a0abc415918536c6add633e047bcb00d5e392b2c
- File type: script · Size: 22575 bytes
- Verdict: suspicious (54/100)
Detections (2 of 50 engines)
- Microsoft Defender: flagged
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://jqueryui.com, http://jquery.org/license, http://api.jqueryui.com/position/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://jqueryui.com
- http://jquery.org/license
- http://api.jqueryui.com/position/
Embedded domains
- jqueryui.com
- jquery.org
- api.jqueryui.com
- m.top
- h.top
- g.top-h.top
- g.top
- i.offset.top
- t.top
- ahanmellat.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report