SUSPICIOUS — 934b1942deabf8f51cd2a53037bf0ea0a934805e563ca77c8182c5e4c4d47157
SUSPICIOUS — 934b1942deabf8f51cd2a53037bf0ea0a934805e563ca77c8182c5e4c4d47157 is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
934b1942deabf8f51cd2a53037bf0ea0a934805e563ca77c8182c5e4c4d47157 - SHA-1:
621ee893870899376fc2d822614f8f3241929248 - MD5:
0a25fed5370ef8d92a29d7c8281eccae - ssdeep:
384:ZPC93LeC4gPDdp+UDVA3QlW5UFB9AM5ybTvbtqri5gbNuze39R21tYZQSdLDcwXN:ZKgC4YDdp+CVA3GrSqSALI0ku - TLSH:
T1502BA3557CC86CCF1649B27E4E801022ED1BDE66B62018D343F4E7429F9CB9B18B8897 - Submitted as: 934b1942deabf8f51cd2a53037bf0ea0a934805e563ca77c8182c5e4c4d47157
- File type: script · Size: 24376 bytes
- Verdict: suspicious (54/100)
Detections (2 of 50 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://docs.woocommerce.com/document/override-loop-template-and-show-quantities-next-to-add-to-cart-buttons/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://docs.woocommerce.com/document/override-loop-template-and-show-quantities-next-to-add-to-cart-buttons/
Embedded domains
- docs.woocommerce.com
- maxundmurat.de
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report