SUSPICIOUS — blockly_compressed.js
SUSPICIOUS — blockly_compressed.js is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 0 of 50 detection engines flagged it.
Identification
- SHA-256:
b3e34ea1b0d8bb10055de06e0e3bf866b4b41f09198f395b1d8380bab39a7b1e - SHA-1:
5b321cc32a1d38ad41451d931b3cd729be343d92 - MD5:
da4bb40e36ab3706e1243fdd1693a924 - ssdeep:
12288:x1PPP51k9OQP9Qaf+5xtyFNZMTpwmzmOh/68bke2a1oDISku3xBIeZc/Eyf0gXF8:x1PX51k9OQP9Qaf+5xtyFNZMTpwmzmOQ - TLSH:
T1FF4D934F3A04EAFC9F4F264B299C9F65F3DAD905E66EA0ED833CD38168E885014450D9 - Submitted as: blockly_compressed.js
- File type: script · Size: 620756 bytes
- Verdict: suspicious (54/100)
Detections (0 of 50 engines)
No engine flagged this sample.
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (layers: base64) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://blockly-demo.appspot.com/static/media/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.w3.org/2000/svg
- http://www.w3.org/1999/xhtml
- http://www.w3.org/1999/xlink
- https://github.com/google/blockly/issues/981
- https://developers.google.com/blockly/xml
- https://blockly-demo.appspot.com/static/media/
Embedded domains
- a.top
- d.y-e.y-f.top
- b-d.top
- f.name
- k.name
- www.w3.org
- github.com
- e.top
- a.style.top
- f.style.top
- this.name
- c.name
- a.name
- developers.google.com
- d.name
- c.top
- blockly-demo.appspot.com
- b.name
- e.name
- d.top
- a.in
- this.in
- this.top
- b.top
- c.bottom-c.top
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report