MALICIOUS — 9f4da2cd0a71ad70bc15359a25400aaad069fd85136a2a84fd25f30fc6996ed6
MALICIOUS — 9f4da2cd0a71ad70bc15359a25400aaad069fd85136a2a84fd25f30fc6996ed6 is a script sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (83/100). 2 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9f4da2cd0a71ad70bc15359a25400aaad069fd85136a2a84fd25f30fc6996ed6 - SHA-1:
6640efc38e39cc89bdf784361cbc5d99e8c4c052 - MD5:
977c50e80ccf74a0bbce29ef10b0b980 - ssdeep:
768:+Otj9+umwo0XCITm9HNfhvwITdNWb0DvHrqgt1ru:+ORjgF9HNfh1TdNWb0DPugt1q - TLSH:
T19F2E514E3D8E7E8DCC4D3C436CEC8193722A9B915A7044ED43BED74AA9B44E8AC0855D - Submitted as: 9f4da2cd0a71ad70bc15359a25400aaad069fd85136a2a84fd25f30fc6996ed6
- File type: script · Size: 30933 bytes
- Verdict: malicious (83/100)
Detections (2 of 54 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 83/100 is the fusion of 3 weighted signals:
- Microsoft Defender flagged Trojan:JS/Agent.AG!MSR (rule
Trojan:JS/Agent.AG!MSR) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75
Dynamic analysis (windows)
6582 behavior events · 1 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 252.0.0.224.in-addr.arpa.
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- ntp.ubuntu.com
- _dosvc._tcp.local
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9?P1=1787953575&P2=404&P3=2&P4=E5fZt9g0nlcfg1NWY7nuXPoin3vulXknmTAx1RnzfNF2S%2fMxa3gnZ%2btpL8Yr147RxujIGeTHFsvWQ2H3QJenaw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Dropped files
- ab619a4fcd4b20ee15b319afdda0a8af0c30881ec2c2d996d88ade01c1e87724 -
ab619a4fcd4b20ee15b319afdda0a8af0c30881ec2c2d996d88ade01c1e87724
Embedded URLs
- https://github.com/harvesthq/chosen/blob/master/LICENSE.md
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9?P1=1787953575&P2=404&P3=2&P4=E5fZt9g0nlcfg1NWY7nuXPoin3vulXknmTAx1RnzfNF2S%2fMxa3gnZ%2btpL8Yr147RxujIGeTHFsvWQ2H3QJenaw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/51d86688-616b-47e3-abeb-3df16a1583c5?P1=1787953599&P2=404&P3=2&P4=kmeMqd%2b%2fXNAbVOtdU18BP4ipPTWR8ertnGOs6zU0KvUDjQqJhV%2fWQMwN44toVO8aXfed3VKsWMM0P4bBS4poEw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/b56480f9-8215-4de7-ba7e-8e690088d21d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5?P1=1787350336&P2=404&P3=2&P4=LwLtYPhuAZbxzoXPHCDSdtW9F4zzIeRXp61c9fAxCl5DYNeXclHEXEGruMxqZO76o3B5YnqLg3A3NqvYyvk5pg%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/b56480f9-8215-4de7-ba7e-8e690088d21d?P1=1787349847&P2=404&P3=2&P4=l%2bgkP98vUteYwy45DAEEk2IhYb0gvqn8pjLsnjxk%2bwrNZ3%2fKSvXZ1FXFI4UfEgWyxmM4rBRyOjjWsY93%2b2K6OQ%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- github.com
- li.no
- endtimesdaily.com
Embedded IP addresses
- 20.42.73.28
- 184.84.165.136
- 57.155.104.224
- 52.110.12.42
- 52.110.12.19
- 4.230.171.124
- 184.84.165.171
- 4.144.132.223
- 52.168.117.168
- 20.231.239.246
- 74.178.76.128
- 52.123.129.14
- 40.99.133.242
- 4.207.44.72
- 52.123.252.242
- 72.153.5.138
- 203.26.79.13
- 74.178.76.44
- 92.223.78.30
- 20.42.65.88
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report