SUSPICIOUS — c1f314347dad3d9db89b3b4b3ee687b2c8b98936643c09f6dd6d276a39d47aa8
SUSPICIOUS — c1f314347dad3d9db89b3b4b3ee687b2c8b98936643c09f6dd6d276a39d47aa8 is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100), attributed to the Wacatac family. 1 of 53 detection engines flagged it.
Identification
- SHA-256:
c1f314347dad3d9db89b3b4b3ee687b2c8b98936643c09f6dd6d276a39d47aa8 - SHA-1:
859e3de0ccf21bbe709c226a691c1cb7e32a08f3 - MD5:
c4c939b8edbfae3a4a406fffd4ae0733 - ssdeep:
384:lQD9QLT29B/G/8uRsMHaK7EBuyEjXpqSnMwIs:lQD919Be8uRHHlbjEs - TLSH:
T1252C841E37C5B5DA841098322E4E44887EE0DC0BFE7544D5C98CCA886ECEA67A464CF7 - Submitted as: c1f314347dad3d9db89b3b4b3ee687b2c8b98936643c09f6dd6d276a39d47aa8
- File type: script · Size: 26655 bytes
- Verdict: suspicious (54/100) · Family: Wacatac
Detections (1 of 53 engines)
- Microsoft Defender: Trojan:Script/Wacatac.C!ml
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://cleverjump.org/counter.js, https://semalt.com, https://semalt.com/?s= - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
1222 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ntp.ubuntu.com
- desktop-hsgcbep
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787873145&P2=404&P3=2&P4=YNXBG3riv1UZKfjmtu43%2f6w0bHkvVMbzhVudVpfXyqm2hLSKmfzOGbAdbd11Qo7GPh9GEejue40FccjCYLTq8w%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787873203&P2=404&P3=2&P4=h%2bxlgl%2fekSep43bp0QliSDc9wodjgcfI%2f5knn3ljJvvkQTg9YfJPupZyTHXJRnEV14vvhS%2f7rz7r8cOkFp3bJg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Embedded URLs
- https://cleverjump.org/counter.js
- https://semalt.com
- https://semalt.com/?s=
- https://semalt.com/popups/popup_wow.php?lang=en
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787873145&P2=404&P3=2&P4=YNXBG3riv1UZKfjmtu43%2f6w0bHkvVMbzhVudVpfXyqm2hLSKmfzOGbAdbd11Qo7GPh9GEejue40FccjCYLTq8w%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787873203&P2=404&P3=2&P4=h%2bxlgl%2fekSep43bp0QliSDc9wodjgcfI%2f5knn3ljJvvkQTg9YfJPupZyTHXJRnEV14vvhS%2f7rz7r8cOkFp3bJg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/b56480f9-8215-4de7-ba7e-8e690088d21d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/9c0462dd-f6cd-4ff7-a7ac-708d0e9dadc5?P1=1787269824&P2=404&P3=2&P4=EqrCDbsjoqwZIbLnjlDWrWVnazFQ8CoQgwBWo5yjc8gCDxldRT7mi5Ea4USO4qqZmO0J37Tuj5NbEAKIML%2bmHA%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/b56480f9-8215-4de7-ba7e-8e690088d21d?P1=1787269422&P2=404&P3=2&P4=BfwlwQSogJggplgkppKSjOUg3gfS%2fy7Y8bHUxlUXoVU7YhG9o99Tva9PbU%2bRwfTW4mfgB6xoDHq4dbn%2blgmrOA%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- kickvox.com
- thegioicua.com
- www.tsgcinc.com
- kapral.com.ua
- charging-box.com
- medtexnika.com.ua
- coinatmshop.com
- www.dzenpharmacy.com
- www.paternityusa.com
- a1researchers.com
- buhgalteriya.com.ua
- www.optimedialabs.ca
- www.trufflesveinspecialists.com
- a-drones.com
- belwooddoors.com.ua
- ls-s.com
- forged.com.ua
- kukolki.com.ua
- www.cslamp.com
- expressramps.com
- maraldi.com.ua
- semalt.com
- drdreheadphonesales.com
- carbongoat.com
- print3dfromhome.com
Embedded IP addresses
- 52.123.252.230
- 4.247.188.224
- 4.144.132.114
- 52.110.12.56
- 52.123.252.193
- 52.110.12.3
- 85.210.193.152
- 4.230.171.124
- 72.154.7.110
- 203.26.79.13
- 52.123.252.246
- 135.232.92.97
- 52.123.252.204
- 135.232.92.137
- 40.99.134.2
- 52.123.129.14
- 40.99.133.242
- 135.233.45.222
- 135.232.92.34
- 92.223.78.30
- 172.170.180.133
- 51.105.71.136
- 52.148.114.188
More Wacatac samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report