SUSPICIOUS — block.js
SUSPICIOUS — block.js is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 1 of 53 detection engines flagged it.
Identification
- SHA-256:
9f8ec2255271bf4fd9ee5b08400d76a69fb49e0986526f0b8c1e4dc5c8b8f70f - SHA-1:
e02616ffbc7521e4446cac12685e0b2b3c709d54 - MD5:
415811ab88732e558741c544d6f63f35 - ssdeep:
192:bc/3i34sgkL+0o7lDv6HRvbMz8PGjvgcBMHaC14s7EBurmr4lhXxnLKIuO:beo8uRzMz8+9MHaK7EBuy0fXxnduO - TLSH:
T15125975A3FDD794A840942A678D82459EED2CC5F518230884474CFD98FEEB36B8F8523 - Submitted as: block.js
- File type: script · Size: 12569 bytes
- Verdict: suspicious (54/100)
Detections (1 of 53 engines)
- Microsoft Defender: Trojan:JS/ScrInject.SQQ!MSR
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://statinside.com/counter.js - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://statinside.com/counter.js
Embedded domains
- gmail.com
- affarity.com
- kegilya.net
- clipsland.com
- ogromnih.net
- vot-potolok.ru
- beprotected.ru
- integrasib.ru
- uniktorg.ru
- veb-privat.ru
- empressleak.xyz
- ewcol.net
- yablonovskiy.ru
- solandge.ru
- samotno.info
- ultimate-survival.ru
- xxxlog.co
- regionstroi-orel.ru
- siegeldisplay.org
- antipont.ru
- zoopressa.ru
- spravkachita.ru
- ob5.ru
- gohikesmart.com
- turmaster.ru
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report