SUSPICIOUS — c2f904998bcebe8444340990c2c0eb0b8de9d8b945030f5b67f7b9e72df24465
SUSPICIOUS — c2f904998bcebe8444340990c2c0eb0b8de9d8b945030f5b67f7b9e72df24465 is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
c2f904998bcebe8444340990c2c0eb0b8de9d8b945030f5b67f7b9e72df24465 - SHA-1:
2cefc50c3c66fe2b141d0c7e339db336500abbab - MD5:
7d092f124b062b8d4de2a9eddc6d8dad - ssdeep:
384:cn50kJuPTb9Uh31//bEP+XgA3S9CleffJmpwsMu:c50KU9Uh31//YWXgA6ffCnMu - TLSH:
T17F295B642FC95BADF9059809FCEA18F287AE3546CDDAE1B1E0ED64910037C91900DEDB - Submitted as: c2f904998bcebe8444340990c2c0eb0b8de9d8b945030f5b67f7b9e72df24465
- File type: script · Size: 19997 bytes
- Verdict: suspicious (54/100)
Detections (2 of 50 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (layers: char-code) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://twemoji.maxcdn.com/v/13.1.0/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://twemoji.maxcdn.com/v/13.1.0/
- http://www.w3.org/TR/SVG11/feature#Image
Embedded domains
- twemoji.maxcdn.com
- www.w3.org
- wiikiihow.com
- wiikiihow.online
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report