SUSPICIOUS — 201988111-lbx__pt_br.js
SUSPICIOUS — 201988111-lbx__pt_br.js is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 0 of 50 detection engines flagged it.
Identification
- SHA-256:
d31bce676025d141cccecf7dcad29d2a38b298fc2bb1ef0efca0fbd89205e992 - SHA-1:
32edede505709fb8ace1f39da985b7963545cbb0 - MD5:
441ebab0b49a1662bd12d41a4b4cfa39 - ssdeep:
6144:Sx4Ma1tK2zeSZqKhXDIHuG0EjKMme5PU:K4ManCSXXcHuSj1y - TLSH:
T1914983DE3886EECEDC4E70AE7D4CA853B3039E54B765A0E082BDC32598E58D43D54825 - Submitted as: 201988111-lbx__pt_br.js
- File type: script · Size: 402553 bytes
- Verdict: suspicious (54/100)
Detections (0 of 50 engines)
No engine flagged this sample.
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated powershell script: dynamic-exec, defense-evasion (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://flickr.com/photos/, 2.0.0.11 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://photos.google.com/lightbox/photoid
- http://flickr.com/photos/
- http://picasaweb.google.com/
- http://google.com/profiles/media/container
- http://google.com/profiles/media/provider
- http://www.google.com/intl/
Embedded domains
- photos.google.com
- a.ga
- pe.prototype.name
- a.be
- ah.prototype.gg
- fh.prototype.gg
- a.gg
- this.uk
- this.cf
- this.kr
- this.jp
- a.cf
- a.to
- m.to
- this.ru
- m.hk
- a.de
- a.hk
- m.de
- this.be
- m.be
- this.ef.hk
- m.za
- b.gg
- this.ua
Embedded IP addresses
- 2.0.0.11
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report