MALICIOUS — be246b5f45a90c86ba194b2cce0a174b360173cef1d0b6d0b6eae30829c23822
MALICIOUS — be246b5f45a90c86ba194b2cce0a174b360173cef1d0b6d0b6eae30829c23822 is a shell sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100). 2 of 54 detection engines flagged it.
Identification
- SHA-256:
be246b5f45a90c86ba194b2cce0a174b360173cef1d0b6d0b6eae30829c23822 - SHA-1:
07fb0378c50ad908f75799d4946845a4ab864f04 - MD5:
270b4b2c1c4c2c08863d9cff94050531 - ssdeep:
1536:h3jB6AZgUjYD9Ty8P85K70zRy+E5DIxB2BHjKBH8ngLAMl:9B6AvjYD9Ty8P84YzQ70xB29080l - TLSH:
T10136849B3ADF094E8244D1B1298D59DAFD110D26710338F802B4E78BEDCDB6B6438A57 - Submitted as: be246b5f45a90c86ba194b2cce0a174b360173cef1d0b6d0b6eae30829c23822
- File type: shell · Size: 69430 bytes
- Verdict: malicious (87/100)
Detections (2 of 54 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 87/100 is the fusion of 4 weighted signals:
- Microsoft Defender flagged Trojan:JS/Agent.AG!MSR (rule
Trojan:JS/Agent.AG!MSR) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://locutus.io/php/number_format/, http://locutus.io/php/empty/, http://stackoverflow.com/a/873856/1489528 - static signal, weight 0.35, confidence 0.60
Dynamic analysis (linux)
865 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- desktop-hsgcbep
- ntp.ubuntu.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 72.145.35.97 IE · Dublin · AS8075 Microsoft Corporation
- 72.145.35.111 IE · Dublin · AS8075 Microsoft Corporation
- ff02::1:3
- 224.0.0.252
- 10.240.0.255
- 10.240.0.1
- ff02::fb
- 224.0.0.251
- ff02::1:ff12:3456
- ff02::16
- 20.184.175.2 US · San Jose · AS8075 Microsoft Corporation
- 185.125.190.58
- ff02::1:ff4c:1d1d
- ff02::1
Embedded URLs
- http://locutus.io/php/number_format/
- http://locutus.io/php/empty/
- http://stackoverflow.com/a/873856/1489528
- https://ipapi.co/jsonp
- https://geo.wpforms.com/v3/geolocate/json
Embedded domains
- element.name
- offset.top
- locutus.io
- stackoverflow.com
- ipapi.co
- geo.wpforms.com
- oralconceptbelgrade.com
Embedded IP addresses
- 1.6.7.1
- 72.145.35.97
- 72.145.35.111
- 20.184.175.2
- 52.168.117.170
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report