SUSPICIOUS — a087174c61632d342b0cbed9fc2ee6b62823fe99aed7df6bdb5afe352cc123c6
SUSPICIOUS — a087174c61632d342b0cbed9fc2ee6b62823fe99aed7df6bdb5afe352cc123c6 is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
a087174c61632d342b0cbed9fc2ee6b62823fe99aed7df6bdb5afe352cc123c6 - SHA-1:
bdf7c4daf20bfe9480c9f8248a71cf8dc7e5f0f6 - MD5:
fc1ffa65d324369bb867d302090186f4 - ssdeep:
1536:WwAIMFFdYMxAcLQD7ZUTSCMEKWsCoyOJalUxHwq7Du:TEY8IiT9FKWsCJUxHnDu - TLSH:
T1853CC5AE3D48BECFCD0E20873E8CA99A77135ED6796494C892BCC7495CB4CE0145C85A - Submitted as: a087174c61632d342b0cbed9fc2ee6b62823fe99aed7df6bdb5afe352cc123c6
- File type: script · Size: 122972 bytes
- Verdict: suspicious (54/100)
Detections (2 of 50 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://gambit.ph, http://dimsemenov.com/plugins/magnific-popup/, http://markgoodyear.com/labs/scrollup/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://gambit.ph
- http://dimsemenov.com/plugins/magnific-popup/
- http://markgoodyear.com/labs/scrollup/
- http://markgoodyear.com
- https://github.com/imakewebthings/jquery-waypoints/blob/master/licenses.txt
- http://kottenator.github.io/jquery-circle-progress/
- https://themeforest.net/user/designing-world
- http://stickyjs.com/
- https://nkdev.info
- https://github.com/nk-o/jarallax
- https://github.com/nk-o/jarallax/issues/53
- https://github.com/nk-o/jarallax/#disable-on-mobile-devices
Embedded domains
- d.top
- e.prototype.to
- this.to
- b.name
- b.property.name
- a.property.name
- img.youtube.com
- vimeo.com
- vzaar.com
- www.youtube.com
- player.vimeo.com
- view.vzaar.com
- c.property.name
- dimsemenov.com
- e.top
- h.top
- youtube.com
- markgoodyear.com
- github.com
- this.config.live
- kottenator.github.io
- gmail.com
- themeforest.net
- stickyjs.com
- nkdev.info
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report