SUSPICIOUS — fp.v3.js
SUSPICIOUS — fp.v3.js is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 0 of 50 detection engines flagged it.
Identification
- SHA-256:
9aa12d141f3c41629c83ac95bf3bebab2b33bca7f8f8988bf64b53b57c73714c - SHA-1:
a1190f7bb41660f682d59e15c2606279da0792f7 - MD5:
1d8ad98fe3471d1a74d485f9b4737bfc - ssdeep:
768:WTW1G6kf2ckxyISuNwxJDJzFE8CYtCgkbAIlIdlIZCwXy:ljvfxyI7N8JDJJEnYsgu3ZRC - TLSH:
T188310997794C9DCCDC396507BEA824677B139F3170E046E4D2AEA3056AE2CD42C31939 - Submitted as: fp.v3.js
- File type: script · Size: 40104 bytes
- Verdict: suspicious (54/100)
Detections (0 of 50 engines)
No engine flagged this sample.
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (layers: base64+char-code+concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://fpjs.dev/pro, https://app.readpeak.com/ads, http://www.eis.de/index.phtml?refid= - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://fpjs.dev/pro
- https://app.readpeak.com/ads
- http://www.eis.de/index.phtml?refid=
- https://www.tipico.com/?affiliateId=
- http://ad2.trafficgate.net/
- https://ad.letmeads.com/
- http://ads.glispa.com/
- http://click.hotlog.ru/
- http://hitcounter.ru/top/stat.php
- http://top.mail.ru/jump
- http://adserv.ontek.com.tr/
- http://izlenzi.com/campaign/
- http://www.installads.net/
- https://xltube.nl/click/
- http://www.rotlichtkartei.com/?sc=
- http://landing.parkplatzkartei.com/?ag=
- http://affiliazioniads.snai.it/
- https://adserver.html.it/
- https://affiliazioniads.snai.it/
- http://pay4results24.eu
- http://axiabanners.exodus.gr/
- http://interactive.forthnet.gr/click
- http://www.salidzini.lv/
- http://promo.vador.com/
- https://aff.sendhub.pl/
Embedded domains
- t.name
- a.top
- r.top
- e.name
- r.name
- fpjs.dev
- app.readpeak.com
- www.eis.de
- www.tipico.com
- ad2.trafficgate.net
- ad.letmeads.com
- www.stumbleupon.com
- telegram.me
- ads.glispa.com
- click.hotlog.ru
- hitcounter.ru
- top.mail.ru
- izlenzi.com
- www.installads.net
- bcebos.com
- xltube.nl
- www.rotlichtkartei.com
- landing.parkplatzkartei.com
- affiliazioniads.snai.it
- adserver.html.it
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report