SUSPICIOUS — d48c1ffc2359233f84ca2802c27c2e4ee5f9b6601e14b9a7a002412b1b555a1c
SUSPICIOUS — d48c1ffc2359233f84ca2802c27c2e4ee5f9b6601e14b9a7a002412b1b555a1c is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
d48c1ffc2359233f84ca2802c27c2e4ee5f9b6601e14b9a7a002412b1b555a1c - SHA-1:
56d26a8e0c5caa4843c6a6fb894db12d294a4950 - MD5:
bf704b382373572330953f57fa00210f - ssdeep:
384:8uMSX9vEqkTVScdV/vWxcHsiW58furhDGXvhHQfww/Xc2S8mFkF50Nsku:iScPy+hkLqkhku - TLSH:
T1D62BFA9BBE4F7E9CC81E856B1D8CBA1A73179A17B55750CD41FDC789ACB08F0085802A - Submitted as: d48c1ffc2359233f84ca2802c27c2e4ee5f9b6601e14b9a7a002412b1b555a1c
- File type: script · Size: 22588 bytes
- Verdict: suspicious (54/100)
Detections (2 of 53 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://jqueryui.com, http://jquery.org/license, http://api.jqueryui.com/position/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://jqueryui.com
- http://jquery.org/license
- http://api.jqueryui.com/position/
Embedded domains
- jqueryui.com
- jquery.org
- api.jqueryui.com
- m.top
- h.top
- g.top-h.top
- g.top
- i.offset.top
- t.top
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report