SUSPICIOUS — add4391e8a280d36e76a2254b6ef3dbadb06e66df4ae764726d46b9cab032e29
SUSPICIOUS — add4391e8a280d36e76a2254b6ef3dbadb06e66df4ae764726d46b9cab032e29 is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (41/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
add4391e8a280d36e76a2254b6ef3dbadb06e66df4ae764726d46b9cab032e29 - SHA-1:
c45844110020c491ac00514850cee424ba6cdbbd - MD5:
a778d91f07576b9eab40828d4bcfcb37 - ssdeep:
48:DVcifj4xsD/ElK72cgppC2qc6mS/IkeWcQbhLJfYK68ZqzeeA:zj4mD/ElKaBppC2qclS+2fP68ku - TLSH:
T18B161181BC091EECC8796252FFC76D433F9EE331525301CD422D5B6768549A22815FBA - Submitted as: add4391e8a280d36e76a2254b6ef3dbadb06e66df4ae764726d46b9cab032e29
- File type: script · Size: 3148 bytes
- Verdict: suspicious (41/100)
Detections (2 of 53 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 41/100 is the fusion of 1 weighted signal:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- alliancehp.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report