SUSPICIOUS — de625233e1b6326660160ec7d5022d3d8c6732ded24791d07e2b99314f067eb5
SUSPICIOUS — de625233e1b6326660160ec7d5022d3d8c6732ded24791d07e2b99314f067eb5 is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
de625233e1b6326660160ec7d5022d3d8c6732ded24791d07e2b99314f067eb5 - SHA-1:
0541e02d565337967225bd14a8e636e3b510b957 - MD5:
bfa79e6bea66b78e9de55147a6e3aaf5 - ssdeep:
3072:UYh8eip3huuf6IidlrvakdtQ47GKxPhQDjI:Ui8eGRuufsr5zQ47GKxPyDs - TLSH:
T1043BE7A7798EADDDCC0D845F3E899C6B77179F29F2E294C4925CCB1468F0CE02868419 - Submitted as: de625233e1b6326660160ec7d5022d3d8c6732ded24791d07e2b99314f067eb5
- File type: script · Size: 102650 bytes
- Verdict: suspicious (54/100)
Detections (2 of 53 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://ptp.pe/wp-includes/js/jquery/jquery.min.js?ver=3.5.1, https://ptp.pe/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.3.2 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ptp.pe/wp-includes/js/jquery/jquery.min.js?ver=3.5.1
- https://ptp.pe/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.3.2
Embedded domains
- jquery.org
- n.top
- e.name
- e.top
- this.name
- t.name
- t.top
- f.top
- t.top-s.top
- ptp.pe
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report