SUSPICIOUS — c953d99a62dd7bcf08737728e622ae3563a2543af5ca409a0c1988a13027dd67
SUSPICIOUS — c953d99a62dd7bcf08737728e622ae3563a2543af5ca409a0c1988a13027dd67 is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (67/100), attributed to the Cryxos family. 1 of 51 detection engines flagged it.
Identification
- SHA-256:
c953d99a62dd7bcf08737728e622ae3563a2543af5ca409a0c1988a13027dd67 - SHA-1:
069335d7b77e9ea43c638857796fc709c384bb4a - MD5:
34d1011b884caf474b6c90025965e5f3 - ssdeep:
96:m5Ev4FfbFSCGG/iSrXZlCytT81FA7IRVSLj:yEEfbFSCGciSrDCytT81FAcRVSLj - TLSH:
T1841AC0F69B317EEF5F8625C5690D1DAF050320C3B400A969E948A9C55C63C991F1CC5C - Submitted as: c953d99a62dd7bcf08737728e622ae3563a2543af5ca409a0c1988a13027dd67
- File type: script · Size: 4439 bytes
- Verdict: suspicious (67/100) · Family: Cryxos
Detections (1 of 51 engines)
- Emsisoft (Emergency Kit): JS:Trojan.Cryxos.6249
Why this verdict
The suspicious score of 67/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged JS:Trojan.Cryxos.6249 (rule
JS:Trojan.Cryxos.6249) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: http://rediskina.com/f/gstats - static signal, weight 0.35, confidence 0.60
- Contacted 8 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Contacted 8 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
854 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- entropy.ubuntu.com
- _dosvc._tcp.local
- ntp.ubuntu.com
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 104.68.2.166
- 23.214.41.230
- 185.125.189.52
- 10.240.0.1
- 224.0.0.251
- ff02::fb
- ff02::1:3
- 224.0.0.252
- 10.240.0.255
- ff02::16
- ff02::1
- ff02::2
- ff02::1:ff4c:1d1d
- ff02::1:2
- 224.0.0.22
Dropped files
- tmp_tmp.UaDp3gmlZg -
b69b51cc75418dcf4173c7cf6361161127a0f5cbccf1a19bd178e8c268c7790c
Embedded URLs
- http://rediskina.com/f/gstats
Embedded domains
- rediskina.com
Embedded IP addresses
- 104.68.2.166
- 23.214.41.230
- 203.26.79.13
- 20.42.73.28
- 149.154.167.99
- 51.105.71.136
More Cryxos samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report