SUSPICIOUS — a48fcda8c1d4d75cf50e5769c721d26e4a20a34f7aee5301e5e927e1777d7416
SUSPICIOUS — a48fcda8c1d4d75cf50e5769c721d26e4a20a34f7aee5301e5e927e1777d7416 is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
a48fcda8c1d4d75cf50e5769c721d26e4a20a34f7aee5301e5e927e1777d7416 - SHA-1:
cd28e7e3533e65d8b103861ea43fa3a422350660 - MD5:
a76e3e03fcf4a8c6e11c9f10973bc135 - ssdeep:
768:Kbckm/AesrwgpWrs7gyqtE+KGrLanCx8te9wwrGFBnxFfQbepYMgd6G5NlVzNKRD:+Lk1SBnxFfQrzxj/CAG4S - TLSH:
T14C315169E8D128644A2E51FD3AC11282FA014C3A303429D593D06F529F9DBFB647CF2B - Submitted as: a48fcda8c1d4d75cf50e5769c721d26e4a20a34f7aee5301e5e927e1777d7416
- File type: script · Size: 40020 bytes
- Verdict: suspicious (54/100)
Detections (2 of 50 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://www.owlgraphic.com/owlcarousel/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.owlgraphic.com/owlcarousel/
Embedded domains
- www.owlgraphic.com
- position.top
- australiancleaningforce.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report