SUSPICIOUS — bootstrap.min.js
SUSPICIOUS — bootstrap.min.js is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (59/100). 0 of 50 detection engines flagged it.
Identification
- SHA-256:
a4555d8dee9f8adc976e84a97dfe87e6bf5794b579f49bb56f133fed85f7d709 - SHA-1:
df0920ee8df5e0a410c714946f22f36846a32a16 - MD5:
c99230d2575380d7f95ff626606d2426 - ssdeep:
768:s1D1OYYUhTVvO1Nn6u7MTLOarIkSsBAiAH0FcQ2K8FXsb6mH/3bz5vhC7V:sF1T145KVdsXc/hhC5 - TLSH:
T1C536A7BA3D4EED4CCC2E42E31D5C6D9A7313BD8BA99940D9D5BDC7D888F49A0249C804 - Submitted as: bootstrap.min.js
- File type: script · Size: 63473 bytes
- Verdict: suspicious (59/100)
Detections (0 of 50 engines)
No engine flagged this sample.
Why this verdict
The suspicious score of 59/100 is the fusion of 4 weighted signals:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://getbootstrap.com/, https://popper.js.org - static signal, weight 0.35, confidence 0.60
- Contacted 5 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (2 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
889 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- ff02::1:3
- 224.0.0.252
- 10.240.0.255
- 224.0.0.251
- ff02::fb
- 10.240.0.1
- ff02::16
- 52.148.114.188 SG · Singapore · AS8075 Microsoft Corporation
- 185.125.190.56
- 239.255.255.250
- 91.189.91.157
- 185.125.190.58
- ff02::1
Dropped files
- tmp_tmp.dpA0glOlUI -
bbf209fe8bf8f976d7892e22776660a9c89f3adff1e9bb03461a2e1e2606abce
Embedded URLs
- https://getbootstrap.com/
- https://github.com/twbs/bootstrap/graphs/contributors
- https://github.com/twbs/bootstrap/blob/main/LICENSE
- https://popper.js.org
Embedded domains
- getbootstrap.com
- github.com
- e.to
- n.to
- popper.js.org
- this.constructor.name
Embedded IP addresses
- 52.148.114.188
- 172.234.27.37
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report