SUSPICIOUS — 855cf6e3cc663061f4a4667a9d8364b4abcc48234690e2e3c6ed02eadb95c0b8
SUSPICIOUS — 855cf6e3cc663061f4a4667a9d8364b4abcc48234690e2e3c6ed02eadb95c0b8 is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (41/100). 1 of 53 detection engines flagged it.
Identification
- SHA-256:
855cf6e3cc663061f4a4667a9d8364b4abcc48234690e2e3c6ed02eadb95c0b8 - SHA-1:
2ef8b8bf4d78241c9f143d9d06f5823a4c009dd4 - MD5:
ab1e0afcb7263fd1b3dd8a71ce2c0dc6 - ssdeep:
96:woqBYnnvgsZS0rmsMyu/F8YCDm4Un9frt:2B2n5g0rIyu/+HDZUBt - TLSH:
T1CE1833336DB8B859D9C40CC9A5709C886CE6FE2FBC25D5CF4B954F84405C3A2E0261AB - Submitted as: 855cf6e3cc663061f4a4667a9d8364b4abcc48234690e2e3c6ed02eadb95c0b8
- File type: script · Size: 3861 bytes
- Verdict: suspicious (41/100)
Detections (1 of 53 engines)
- Microsoft Defender: Trojan:HTML/Phish.AMK!MTB
Why this verdict
The suspicious score of 41/100 is the fusion of 1 weighted signal:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report