SUSPICIOUS — 998ab20451d9d4322ccabe305b175adf90e81e72b0e0ac6699c6a338c50bb6ea
SUSPICIOUS — 998ab20451d9d4322ccabe305b175adf90e81e72b0e0ac6699c6a338c50bb6ea is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
998ab20451d9d4322ccabe305b175adf90e81e72b0e0ac6699c6a338c50bb6ea - SHA-1:
107717220fd14745e02723aa413aa3d6b7678ec6 - MD5:
a0cb571d31c91ff8056e8ca808d38770 - ssdeep:
768:q1+7/uRE672wlNrDMlbGqXYu+jS1s8ep0s1QfrXf8X8GEpZOWUsu:eFRx7zYyS1WOv8UpZDUz - TLSH:
T16A30E69D7C48BFCCDC0E21F75ECCA9567B02A505AB9598EEC2BEE3445CF88801958817 - Submitted as: 998ab20451d9d4322ccabe305b175adf90e81e72b0e0ac6699c6a338c50bb6ea
- File type: script · Size: 37404 bytes
- Verdict: suspicious (54/100)
Detections (2 of 50 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://getbootstrap.com - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://getbootstrap.com
- https://github.com/twbs/bootstrap/blob/master/LICENSE
Embedded domains
- getbootstrap.com
- github.com
- e.to
- c.prototype.to
- b.to
- k.top
- p.top
- b.top
- a.top
- e.bottom-e.top
- g.top
- e.top
- f.top
- d.top
- d.offset.top
- eccoplastic.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report