MALICIOUS — dbf7c9c6304a1c65a91e90fec67f0befbf274a024f2f8f64db04ed1d37c8ed72
MALICIOUS — dbf7c9c6304a1c65a91e90fec67f0befbf274a024f2f8f64db04ed1d37c8ed72 is a script sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (83/100). 2 of 54 detection engines flagged it.
Identification
- SHA-256:
dbf7c9c6304a1c65a91e90fec67f0befbf274a024f2f8f64db04ed1d37c8ed72 - SHA-1:
6d886af324bca3c8693184d04d2580b23d0258ff - MD5:
1df454b3e82a58362838e4b9dab29bcc - ssdeep:
96:KoG0hb888888881Nvuy06OQGYhb88888888juuCppC2+clS+2fP68ku:xGhLiGVuCps2ozfPku - TLSH:
T1A11AE19E3CA529EF954E4276BB86380F6DCEB3C35112408195985F1B0452FE31808B2E - Submitted as: dbf7c9c6304a1c65a91e90fec67f0befbf274a024f2f8f64db04ed1d37c8ed72
- File type: script · Size: 4622 bytes
- Verdict: malicious (83/100)
Detections (2 of 54 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 83/100 is the fusion of 3 weighted signals:
- Microsoft Defender flagged Trojan:JS/Agent.AG!MSR (rule
Trojan:JS/Agent.AG!MSR) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75
Dynamic analysis (windows)
1126 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- desktop-hsgcbep(2)._dosvc._tcp.local
- desktop-hsgcbep(3)._dosvc._tcp.local
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Embedded domains
- nisarbabu.info
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 52.168.112.67
- 74.178.240.61
- 57.154.63.210
- 57.155.101.212
- 85.210.196.11
- 20.42.65.94
- 85.210.193.152
- 4.144.132.114
- 52.110.12.24
- 52.110.12.14
- 4.230.171.124
- 74.178.76.128
- 20.42.65.90
- 51.116.246.104
- 72.145.35.105
- 20.184.175.5
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report