MALICIOUS — c33b92a94057ac16264b8bc1702a08a73aef36981626a2a2cb06a66963b4c8f2
MALICIOUS — c33b92a94057ac16264b8bc1702a08a73aef36981626a2a2cb06a66963b4c8f2 is a script sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100). 2 of 54 detection engines flagged it.
Identification
- SHA-256:
c33b92a94057ac16264b8bc1702a08a73aef36981626a2a2cb06a66963b4c8f2 - SHA-1:
c84a3b9fced3e8f558061e6137bb909a32b4fa87 - MD5:
b514427040923300d2e785bd84dc1a18 - ssdeep:
1536:lSLrzY0ndK0pk9OgPoY+2wf5KjqsIJ4Z:lK3SvmwZ - TLSH:
T19638D7AF3AE53DDF590A06957A4C202F75071ED235022094C668EF898CBFF66592C12B - Submitted as: c33b92a94057ac16264b8bc1702a08a73aef36981626a2a2cb06a66963b4c8f2
- File type: script · Size: 78892 bytes
- Verdict: malicious (87/100)
Detections (2 of 54 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 87/100 is the fusion of 4 weighted signals:
- Microsoft Defender flagged Trojan:JS/Agent.AG!MSR (rule
Trojan:JS/Agent.AG!MSR) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec, defense-evasion (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://maps.googleapis.com/maps/api/js, https://api.flickr.com/services/rest/?format=json&method=, https://goo.gl/ku3NgH - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
1144 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- desktop-hsgcbep(2)._dosvc._tcp.local
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.209
- 172.66.2.5 US · San Francisco · AS13335 Cloudflare, Inc.
- 23.11.37.157
- 20.190.142.164
- 20.184.175.23 US · San Jose · AS8075 Microsoft Corporation
- 52.123.252.220 AU · Sydney · AS8075 Microsoft Corporation
- 192.168.122.114
- 23.198.40.44
Dropped files
- 2452978cb35ff6df2a2b12553cb2b9bb0dccabc8b80c3419ae68b3d2c30d6c2d -
2452978cb35ff6df2a2b12553cb2b9bb0dccabc8b80c3419ae68b3d2c30d6c2d
Embedded URLs
- https://maps.googleapis.com/maps/api/js
- https://api.flickr.com/services/rest/?format=json&method=
- https://goo.gl/ku3NgH
- https://www.youtube.com/iframe_api
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- maps.googleapis.com
- api.flickr.com
- static.flickr.com
- www.youtube.com
- player.vimeo.com
- amcare.org
- goo.gl
Embedded IP addresses
- 104.208.16.94
- 172.66.2.5
- 20.184.175.23
- 52.123.252.220
- 52.110.12.18
- 4.230.171.124
- 40.84.97.4
- 52.253.84.76
- 20.42.65.91
- 72.154.7.16
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report