SUSPICIOUS — a219dfaf4b5acc45855fdd5fc1e5278f8614f257c1f4c99dd895c99e93fa476f
SUSPICIOUS — a219dfaf4b5acc45855fdd5fc1e5278f8614f257c1f4c99dd895c99e93fa476f is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (65/100), attributed to the Gootloader family. 3 of 53 detection engines flagged it.
Identification
- SHA-256:
a219dfaf4b5acc45855fdd5fc1e5278f8614f257c1f4c99dd895c99e93fa476f - SHA-1:
1963bee80f1e79212d99403b7bb8e39e222b3134 - MD5:
d4103d30462e5a0c9f12f496e8c73457 - ssdeep:
3072:ft0BHcYqQ7A+76yAqxlhjlKws8RynhAxNBErOEqoPLwa4f:iJ7xAohj4wrynuBErOEqoPcb - TLSH:
T1924AE63B3DCD59CFA84D06152AC8795EF9131EA1314174D98184EB87CCACBAB6438C6B - Submitted as: a219dfaf4b5acc45855fdd5fc1e5278f8614f257c1f4c99dd895c99e93fa476f
- File type: script · Size: 458112 bytes
- Verdict: suspicious (65/100) · Family: Gootloader
Detections (3 of 53 engines)
- YARA: SophosLabs IoCs (public): SOPHOS_Gootloader_JS
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 65/100 is the fusion of 3 weighted signals:
- Obfuscated powershell script: dynamic-exec, defense-evasion (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - YARA: SophosLabs IoCs (public) flagged SOPHOS_Gootloader_JS (rule
SOPHOS_Gootloader_JS) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://gsgd.co.uk/sandbox/jquery/easing/, http://brandon.aaron.sh, http://www.woothemes.com/flexslider/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://gsgd.co.uk/sandbox/jquery/easing/
- http://brandon.aaron.sh
- http://www.woothemes.com/flexslider/
- http://www.gnu.org/licenses/gpl-2.0.html
- http://ricostacruz.com/jquery.transit
- http://github.com/rstacruz/jquery.transit
- https://github.com/louisremi/jquery.smartresize.js
- http://www.w3.org/2000/svg
- http://www.codrops.com
- http://www.opensource.org/licenses/mit-license.php
- http://imakewebthings.com/waypoints/shortcuts/sticky-elements
- https://www.facebook.com/sharer/sharer.php?u=
- https://plus.google.com/share?url=
- http://twitter.com/intent/tweet?text=
- http://www.linkedin.com/shareArticle?mini=true&url=
- http://pinterest.com/pin/create/button/?url=
- https://graph.facebook.com/?id=
- https://cdn.api.twitter.com/1/urls/count.json?url=
- https://www.linkedin.com/countserv/count/share?url=
- https://api.pinterest.com/v1/urls/count.json?url=
- http://roy-jin.appspot.com/jsp/textareaCounter.jsp
- http://www.gnu.org/licenses/gpl.html
- http://cherne.net/brian/resources/jquery.hoverIntent.html
Embedded domains
- i.top
- this.name
- t.name
- gsgd.co.uk
- brandon.aaron.sh
- www.woothemes.com
- www.gnu.org
- ricostacruz.com
- github.com
- settings.to
- span.in
- www.w3.org
- container-wrap.no
- twitch.tv
- www.codrops.com
- www.opensource.org
- html.no
- ajax-content-wrap.no
- imakewebthings.com
- offsets.top
- www.facebook.com
- plus.google.com
- twitter.com
- www.linkedin.com
- pinterest.com
More Gootloader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report