MALICIOUS — b7ef6e52313fffd8a52470307d2b0b7d646e69bd7fbc5123be008ee7c617fa60
MALICIOUS — b7ef6e52313fffd8a52470307d2b0b7d646e69bd7fbc5123be008ee7c617fa60 is a script sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (70/100), attributed to the Base64 family. 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b7ef6e52313fffd8a52470307d2b0b7d646e69bd7fbc5123be008ee7c617fa60 - SHA-1:
3d4b874717cc01cb1528bd23fbb114a642b8b6dc - MD5:
fabf9c0ee0261f6d73c990e21d8be750 - ssdeep:
96:lFT6T/vXhDGR8jyhwjM5iXT/qRKGUPnT6jkhg/3nHmn7uT5Zh3X:lFqvXhjyhwgQj/z8f3Gn7uTbhn - TLSH:
T1961D8F085E31BFA60D50AF22415F36CAC5E161648102F0D0FDE8907DAE7AF713DA5BA2 - Submitted as: b7ef6e52313fffd8a52470307d2b0b7d646e69bd7fbc5123be008ee7c617fa60
- File type: script · Size: 6297 bytes
- Verdict: malicious (70/100) · Family: Base64
Detections (5 of 53 engines)
- capa (capabilities): capability:execution/powershell
- YARA: MalwareAnalyser community pack: TL_Base64_EncodedCommand
- Microsoft Defender: Trojan:PowerShell/Rozena.HNAB!MTB
- Emsisoft (Emergency Kit): Trojan.Generic.32238828
- Kaspersky (KVRT): HEUR:Trojan.PowerShell.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 70/100 is the fusion of 3 weighted signals:
- Obfuscated powershell script: shellcode-injection (layers: powershell-encodedcommand+base64) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - YARA: MalwareAnalyser community pack flagged TL_Base64_EncodedCommand (rule
TL_Base64_EncodedCommand) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis (windows)
1144 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- _http._tcp.security.ubuntu.com
- _http._tcp.archive.ubuntu.com
- security.ubuntu.com
- security.ubuntu.com.cdn.cloudflare.net
- archive.ubuntu.com
- _https._tcp.motd.ubuntu.com
- motd.ubuntu.com
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787850376&P2=404&P3=2&P4=PYWE7kS%2fFXhnTOui6j3MH63lSrjPk7n0j1324ty1LWim%2bM%2b7gRgzQxNExSOljCGnjNdLpqKiimOCuPWhUSIedg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787850403&P2=404&P3=2&P4=HeyTfCl0FAj8KYvfdfsAVlkW4cEwnRj5PaG%2bguJTASgx32GAxBI%2fgzH%2b15HisM6Y7JB7pxLp%2bksUfGDJ37mtjw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/b56480f9-8215-4de7-ba7e-8e690088d21d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5?P1=1787247056&P2=404&P3=2&P4=bUDZyT%2fg2gASM8RrCh587XjCoR0Q%2b2Ex0opX3eADcyAJ4Yt52S0ahBfh7W7svvXAh9VkQBsf%2bLMUhSe150Ynqw%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/b56480f9-8215-4de7-ba7e-8e690088d21d?P1=1787246614&P2=404&P3=2&P4=Z8O%2bvd3CtRnDJQaqdJHhu9McS22fbjBG06L7LdA5TrGsmDl1aLxjLh%2b4ewvhEQcwlNB0AFn0v7Ewumj9j%2bM%2bLA%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- security.ubuntu.com.cdn.cloudflare.net
Embedded IP addresses
- 34.253.181.30
- 74.179.77.204
- 3.254.173.149
- 172.172.255.216
- 104.20.28.246
- 172.66.152.176
- 135.233.45.222
- 85.210.196.11
- 48.211.4.16
- 52.123.252.222
- 4.230.171.124
- 52.230.60.54
- 74.178.240.61
- 20.76.201.171
- 135.233.95.144
- 52.123.128.14
- 40.99.133.242
- 20.184.175.9
- 135.233.45.221
- 52.123.252.218
- 72.145.35.109
- 203.26.79.13
- 20.42.179.204
- 20.42.73.25
- 20.165.94.46
File paths
- C:\\Windows\\syswow64\\WindowsPowerShell\\v1.0\\powershell.exe\
More Base64 samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report