SUSPICIOUS — bfc7b0fd6a18d8dfe3f2e89cdda7a69114609781f2f62aedf4ea71e2e9a9bcde
SUSPICIOUS — bfc7b0fd6a18d8dfe3f2e89cdda7a69114609781f2f62aedf4ea71e2e9a9bcde is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100), attributed to the Redirector family. 1 of 53 detection engines flagged it.
Identification
- SHA-256:
bfc7b0fd6a18d8dfe3f2e89cdda7a69114609781f2f62aedf4ea71e2e9a9bcde - SHA-1:
41670b403fcb0c8bdd9fb8715179015b8a38df22 - MD5:
9a987d73211ee4a39bd77bf73112d796 - ssdeep:
192:Cb9a9I97Ub9jb9eb914b9Xb98H8yrbTIMjLtnUziXkRCYr:Cb9a9I9ob9jb9eb9ib9Xb9hyrwMjL1Ut - TLSH:
T11623401DBDC0DECA9D4A22E919DF1D996E32C0573B0AE8FD44A4E38E96948F008CD419 - Submitted as: bfc7b0fd6a18d8dfe3f2e89cdda7a69114609781f2f62aedf4ea71e2e9a9bcde
- File type: script · Size: 10947 bytes
- Verdict: suspicious (54/100) · Family: Redirector
Detections (1 of 53 engines)
- Microsoft Defender: Trojan:JS/Redirector.ARF!MTB
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (layers: char-code) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://port.transandfiestas.ga/js.php?from=w&sid=515, https://stop.transandfiestas.ga/m.js, https://irc.transandfiestas.ga/m.js - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
1207 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787873458&P2=404&P3=2&P4=dN2ugXcMafeFi2d6QZprDSKyK4Qco8L7y%2fGjnn3fY4XvBtLwdYP%2fvJo2eg8yBnC9jyJaFdjXTVi%2b8mSq%2fjrS8A%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787873507&P2=404&P3=2&P4=aJPuegd5FNvFoIWUKC6I5Y%2bZtQc2vPg7gjJrJ%2fijXQxSps4%2bmFv8gljUZY8ulYH1uJtlW%2bzHP80cM1T5zCNwvw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- 92.223.78.30 AU · Sydney · AS199524 G-Core Labs Customer assignment
Embedded URLs
- https://github.com/gijsroge/tilt.js/pull/26
- https://port.transandfiestas.ga/js.php?from=w&sid=515
- https://stop.transandfiestas.ga/m.js
- https://irc.transandfiestas.ga/m.js
- https://start.transandfiestas.ga/m.js
- https://well.linetoadsactive.com/m.js
- https://port.lovegreenpencils.ga/m.js
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787873458&P2=404&P3=2&P4=dN2ugXcMafeFi2d6QZprDSKyK4Qco8L7y%2fGjnn3fY4XvBtLwdYP%2fvJo2eg8yBnC9jyJaFdjXTVi%2b8mSq%2fjrS8A%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787873507&P2=404&P3=2&P4=aJPuegd5FNvFoIWUKC6I5Y%2bZtQc2vPg7gjJrJ%2fijXQxSps4%2bmFv8gljUZY8ulYH1uJtlW%2bzHP80cM1T5zCNwvw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- github.com
- main.travelfornamewalking.ga
- port.transandfiestas.ga
- stop.transandfiestas.ga
- irc.transandfiestas.ga
- start.transandfiestas.ga
- well.linetoadsactive.com
- port.lovegreenpencils.ga
Embedded IP addresses
- 135.232.92.34
- 51.105.71.137
- 92.223.78.30
- 162.159.142.9
- 20.184.175.15
- 52.110.12.3
- 4.230.171.124
- 20.42.179.204
- 20.247.184.197
- 135.232.92.137
- 20.231.239.246
- 135.233.95.144
- 52.123.128.14
- 4.150.223.109
- 203.26.79.13
- 4.247.188.224
More Redirector samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report