MALICIOUS — 8793724f0317597456f0e5e8f62b3d28f0626048963155dd6710ea6fcb1ca14f
MALICIOUS — 8793724f0317597456f0e5e8f62b3d28f0626048963155dd6710ea6fcb1ca14f is a script sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (72/100), attributed to the Base64 family. 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8793724f0317597456f0e5e8f62b3d28f0626048963155dd6710ea6fcb1ca14f - SHA-1:
04d8f98885974333e087b8ff9917242f7841afcf - MD5:
769d16fca2c82d1a6112c0c31eda9f0f - ssdeep:
96:ET6T/vXhDGR8jyhwjVNKwNIIauWg/hCTkmoqpGpOGLXD3F2CZ/3nz+SaTwQXhE:EqvXhjyhwL9/9A9s3zKTwQXhE - TLSH:
T19E1F5B496D71BFA60C51AF22425F35CAC5E162248001B0D0FDD8907DEE7AF713EA5BA2 - Submitted as: 8793724f0317597456f0e5e8f62b3d28f0626048963155dd6710ea6fcb1ca14f
- File type: script · Size: 7385 bytes
- Verdict: malicious (72/100) · Family: Base64
Detections (4 of 50 engines)
- capa (capabilities): capability:execution/powershell
- YARA: MalwareAnalyser community pack: TL_Base64_EncodedCommand
- Kaspersky (KVRT): HEUR:Trojan.PowerShell.Generic
- Microsoft Defender: Trojan:PowerShell/Rozena.HNAB!MTB
MITRE ATT&CK
Why this verdict
The malicious score of 72/100 is the fusion of 4 weighted signals:
- Obfuscated powershell script: shellcode-injection (layers: powershell-encodedcommand+base64) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - YARA: MalwareAnalyser community pack flagged TL_Base64_EncodedCommand (rule
TL_Base64_EncodedCommand) - engine signal, weight 0.35, confidence 0.70 - Contacted 6 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (linux)
870 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- 224.0.0.251
- ff02::fb
- ff02::1:3
- 224.0.0.252
- 10.240.0.1
- ff02::16
- 185.125.190.56
- 239.255.255.250
- ff02::1
- ff02::2
- ff02::1:ff12:3456
- 74.179.77.204 US · Moses Lake · AS8075 Microsoft Corporation
- 48.211.4.16 US · Ashburn · AS8075 Microsoft Limited
- 91.189.91.157
- 255.255.255.255
- 224.0.0.22
- 40.126.14.161
- 57.155.101.212 SG · Singapore · AS8075 Microsoft Limited UK
Dropped files
- tmp_tmp.T5fD8Bcu7q -
c4afc9c05b120d912f996bfd23413f6e3215d3db22f7ec666aae8d3cbc88ba87
Embedded IP addresses
- 74.179.77.204
- 48.211.4.16
- 57.155.101.212
File paths
- C:\\Windows\\syswow64\\WindowsPowerShell\\v1.0\\powershell.exe\
More Base64 samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report