SUSPICIOUS — d90743cc3e41706b7f469a40a53069ce160bca98ae329302871865145b4405c9
SUSPICIOUS — d90743cc3e41706b7f469a40a53069ce160bca98ae329302871865145b4405c9 is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (41/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
d90743cc3e41706b7f469a40a53069ce160bca98ae329302871865145b4405c9 - SHA-1:
970f516f17ed987e8600538619b2ea3431dd4880 - MD5:
028c2549bd063b031142f1fc52dac0db - ssdeep:
96:Jk33MiWDbefwG4M6ppC2hPclS+2fP68ku:asi9oGwps2h/zfPku - TLSH:
T1DD1784A1388917F4C84B9196FFCB74437F5FD612B6139080868DDDA220A58C53D1CA3D - Submitted as: d90743cc3e41706b7f469a40a53069ce160bca98ae329302871865145b4405c9
- File type: script · Size: 3620 bytes
- Verdict: suspicious (41/100)
Detections (2 of 50 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 41/100 is the fusion of 1 weighted signal:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://github.com/js-cookie/js-cookie
Embedded domains
- github.com
- talkualfoods.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report