SUSPICIOUS — d379f11ece6244543cb65684c914570c985a73320a46cb6e0bfffb103440c835
SUSPICIOUS — d379f11ece6244543cb65684c914570c985a73320a46cb6e0bfffb103440c835 is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
d379f11ece6244543cb65684c914570c985a73320a46cb6e0bfffb103440c835 - SHA-1:
41f9a9b952584ad2835d1feb412f6720470f62ba - MD5:
3eb6620eda7ce515967cc1a848dba308 - ssdeep:
192:CH8H8H8H8H8H8H8H8HTyTKjKcP87NHUTKx4TZndlNZjwFuA5TXG6svOOX8DHJaDZ:6OVUTK+ZMl5TgvOOX8DpaDvIVsIu - TLSH:
T14426758679CADF98CC1F55561DCEF5626B4B863B7AC0A0D8826EE33994A4DB02D0CC11 - Submitted as: d379f11ece6244543cb65684c914570c985a73320a46cb6e0bfffb103440c835
- File type: script · Size: 14950 bytes
- Verdict: suspicious (54/100)
Detections (2 of 50 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://incsub.com, http://www.gnu.org/licenses/gpl-3.0.html - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://incsub.com
- http://www.gnu.org/licenses/gpl-3.0.html
Embedded domains
- incsub.com
- www.gnu.org
- alliancehp.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report