SUSPICIOUS — FACTURA.js
SUSPICIOUS — FACTURA.js is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (41/100). 1 of 53 detection engines flagged it.
Identification
- SHA-256:
afb37dc0678f295bdae2708f5b840230f90711ced3ee1c753e9a0238d4f64eb1 - SHA-1:
5bac2b105cf0f2196664662da2da80073c5c1b51 - MD5:
4432f2a92b531c0e4f578b5d832ad657 - ssdeep:
24576:7RfUv7HBTAvDOYLxk/fawXVmbfUpgqa2cjMxW88XCq704Qxp/N8kxI7dNNAnYxYf:lu7hM64/kVN6MEoK5VK48Ej4ay - TLSH:
T18B5BD86ABDC6E46F206413C83CDE240945B9E6DAC83056647C43BFED8DB7DC5E42A848 - Submitted as: FACTURA.js
- File type: script · Size: 2168454 bytes
- Verdict: suspicious (41/100)
Detections (1 of 53 engines)
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 41/100 is the fusion of 1 weighted signal:
- Obfuscated powershell script: dynamic-exec, wmi, defense-evasion (layers: base64) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
File paths
- C:\x5cTemp\x5c
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report