SUSPICIOUS — codeMirror.plugin.min.js
SUSPICIOUS — codeMirror.plugin.min.js is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (41/100). 0 of 50 detection engines flagged it.
Identification
- SHA-256:
c87f083330dda171b3a1c1b912c218591aa9bb6b0b82b5f3c2ded5fea912f4b8 - SHA-1:
95b01cc20c287b6efb9e0983b5c0a06a3896ad0d - MD5:
07dfaa7d4e6b4226846b720206efa740 - ssdeep:
1536:Vhn9ei19zkW0zfYZAtcidEDjhE4n/DDcdqS3/mb:Vhn9X5kW0zfj9EDuqd - TLSH:
T1E735F77B39CD799CCC0E905B3D98A8AB77138A6EF6A180C4D3ADC74471B58A01934C5E - Submitted as: codeMirror.plugin.min.js
- File type: script · Size: 60641 bytes
- Verdict: suspicious (41/100)
Detections (0 of 50 engines)
No engine flagged this sample.
Why this verdict
The suspicious score of 41/100 is the fusion of 1 weighted signal:
- Obfuscated javascript script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- l.style.top
- v.top
- e.from.ch
- t.top
- n.to
- e.to
- n.length-t.ch
- t.ch
- o.ch
- n.ch
- this.pos.to
- t.to
- t.from.ch
- t.to.ch
- this.pos.from.ch
- o.to
- r.ch
- a.to
- f.ch
- l.from.ch
- l.to
- l.to.ch
- s.ch
- p.ch
- y.ch
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report