MALICIOUS — 91e8f8c35975db6df82e0a3996ae89ed1af6810179f018e4d131ac4ae654116f
MALICIOUS — 91e8f8c35975db6df82e0a3996ae89ed1af6810179f018e4d131ac4ae654116f is a script sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the Base64 family. 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
91e8f8c35975db6df82e0a3996ae89ed1af6810179f018e4d131ac4ae654116f - SHA-1:
73bf4a000fa72a50ec965b91d90f0cf4dc85aa98 - MD5:
109f9e8563fdb23cad50bc3b9d600856 - ssdeep:
96:wGjsGPW0aKUuCqVQwODKB57JojU8jSc49SCREnTiw0jG:jtPQKuqVLOD6LwJjS/9SCREnTipG - TLSH:
T1E31832AA3E5261890187733688A712C4C56C7A5E98A6F2A323E3F3691D71F3371093D0 - Submitted as: 91e8f8c35975db6df82e0a3996ae89ed1af6810179f018e4d131ac4ae654116f
- File type: script · Size: 3931 bytes
- Verdict: malicious (92/100) · Family: Base64
Detections (4 of 50 engines)
- capa (capabilities): capability:execution/powershell
- YARA: MalwareAnalyser community pack: TL_Base64_EncodedCommand
- Microsoft Defender: VirTool:PowerShell/Empire.MM!MTB
- Kaspersky (KVRT): HEUR:Trojan.PowerShell.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 92/100 is the fusion of 6 weighted signals:
- Microsoft Defender flagged VirTool:PowerShell/Empire.MM!MTB (rule
VirTool:PowerShell/Empire.MM!MTB) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.PowerShell.Generic (rule
HEUR:Trojan.PowerShell.Generic) - engine signal, weight 0.55, confidence 0.85 - Obfuscated powershell script: download, dynamic-exec, encoded-command, defense-evasion (layers: powershell-encodedcommand+base64) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - YARA: MalwareAnalyser community pack flagged TL_Base64_EncodedCommand (rule
TL_Base64_EncodedCommand) - engine signal, weight 0.35, confidence 0.70 - Contacted 1 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (linux)
828 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- 250.255.255.239.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 169.254.255.255
- ff02::1:3
- 224.0.0.252
- ff02::fb
- 224.0.0.251
- 10.240.0.255
- ff02::16
- 10.240.0.1
- ff02::2
- ff02::1
- 239.255.255.250
- 20.165.94.63 US · San Antonio · AS8075 Microsoft Corporation
- 255.255.255.255
- ff02::1:2
Dropped files
- tmp_tmp.8m3eXgcdx6 -
5a0a91ba42575f1e1971fe7190166bb85f137fbc7f8cc7dab166f1b63212f11d
Embedded IP addresses
- 20.165.94.63
File paths
- C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
More Base64 samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report