SUSPICIOUS — be1d2d89603182c19507a2c8a80afa45cab9aa9b228db4eb88e4a5c335b11668
SUSPICIOUS — be1d2d89603182c19507a2c8a80afa45cab9aa9b228db4eb88e4a5c335b11668 is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
be1d2d89603182c19507a2c8a80afa45cab9aa9b228db4eb88e4a5c335b11668 - SHA-1:
576d133a87dd0df319123904da24100725a7bd6c - MD5:
e1d23d993635a89bffe9d2b401d97438 - ssdeep:
1536:dWkvcMg2KWspIpiHJO986EzOQth8ZqLx2nPce0P4NnVOjaubEs9D6HD6kx4iDz3h:FKWspIVghth8ZE0ce0P4NniD6HD6kx4y - TLSH:
T19739C78D3CC96F8CCD0D51D63ECCA99A73239A5576A9D4E8C3BCE750A9B08F04C8441A - Submitted as: be1d2d89603182c19507a2c8a80afa45cab9aa9b228db4eb88e4a5c335b11668
- File type: script · Size: 86404 bytes
- Verdict: suspicious (54/100)
Detections (2 of 53 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated powershell script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://css-tricks.com, http://daverupert.com, http://www.alistapart.com/articles/creating-intrinsic-ratios-for-video/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
1425 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- desktop-hsgcbep
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9?P1=1787946989&P2=404&P3=2&P4=Kn0slDvfBsF3fg6S2S3uaALc1AQsCB85LnnHyW%2bnOH9Hhz43MRqekRNbNOETb3cwRYM%2bbjGcBGcouJzKulHCEQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/51d86688-616b-47e3-abeb-3df16a1583c5?P1=1787947049&P2=404&P3=2&P4=Kznm%2fG41UWBqIoeHQZVeB2N%2fLZnBkBfSM3kuA9XdOfd3RrQYib3nh%2fzS9Iiw5Gx6uNO1rbcHirvRGj9FrA5C3Q%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Dropped files
- c9755626dc83b13f603a7add12ae1e9e3970354b44c707f4ffab459f19ef7315 -
c9755626dc83b13f603a7add12ae1e9e3970354b44c707f4ffab459f19ef7315
Embedded URLs
- https://github.com/nicinabox/superslides
- https://github.com/imakewebthings/jquery-waypoints/blob/master/licenses.txt
- https://github.com/mhuggins/jquery-countTo
- http://css-tricks.com
- http://daverupert.com
- http://www.alistapart.com/articles/creating-intrinsic-ratios-for-video/
- http://sam.zoy.org/wtfpl/
- http://www.ianlunn.co.uk/plugins/jquery-parallax/
- http://www.opensource.org/licenses/mit-license.php
- http://www.gnu.org/licenses/gpl.html
- http://www.owlgraphic.com/owlcarousel/
- http://isotope.metafizzy.co
- http://bit.ly/getsizebug1
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9a8a705c-852d-4d18-b32a-ee1d872f4bd9?P1=1787946989&P2=404&P3=2&P4=Kn0slDvfBsF3fg6S2S3uaALc1AQsCB85LnnHyW%2bnOH9Hhz43MRqekRNbNOETb3cwRYM%2bbjGcBGcouJzKulHCEQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/51d86688-616b-47e3-abeb-3df16a1583c5?P1=1787947049&P2=404&P3=2&P4=Kznm%2fG41UWBqIoeHQZVeB2N%2fLZnBkBfSM3kuA9XdOfd3RrQYib3nh%2fzS9Iiw5Gx6uNO1rbcHirvRGj9FrA5C3Q%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- github.com
- e.top
- this.options.to
- css-tricks.com
- daverupert.com
- www.alistapart.com
- sam.zoy.org
- player.vimeo.com
- youtube.com
- youtube-nocookie.com
- kickstarter.com
- www.ianlunn.co.uk
- www.opensource.org
- www.gnu.org
- www.owlgraphic.com
- y-e.top
- isotope.metafizzy.co
- bit.ly
- t.to
- t.top
- n.top
- odszkodowanialeicester.co.uk
Embedded IP addresses
- 4.150.223.107
- 40.84.97.4
- 20.42.73.24
- 52.168.117.170
- 20.42.65.85
- 172.172.255.216
- 74.178.76.128
- 162.159.142.9
- 48.211.4.16
- 52.110.12.54
- 4.230.171.124
- 135.232.92.137
- 135.232.92.97
- 20.236.44.162
- 52.123.128.14
- 135.233.45.222
- 52.123.252.194
- 72.153.5.129
- 203.26.79.13
- 172.178.240.162
- 40.84.85.40
- 4.150.223.104
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report