SUSPICIOUS — e10f2a1e2dd8f9b6de2dba4dc6834c0b89fe52f1fe3918f71cd29529edb5244e
SUSPICIOUS — e10f2a1e2dd8f9b6de2dba4dc6834c0b89fe52f1fe3918f71cd29529edb5244e is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
e10f2a1e2dd8f9b6de2dba4dc6834c0b89fe52f1fe3918f71cd29529edb5244e - SHA-1:
02902deef75c5b1daa991af7267a97a3d9408db8 - MD5:
7b1c951fba2e41c01c4ca62cb3d40f28 - ssdeep:
6144:6cg560pzeNp0xqIUnfZjAWJ72RzEOQ0+iea98Hrmv:lg560tDxqYYOz+iZ - TLSH:
T152462A9778DDAEDDCC0E546F3E8CA86737139E69B5A264C0828CCB0459F5EE02C6C416 - Submitted as: e10f2a1e2dd8f9b6de2dba4dc6834c0b89fe52f1fe3918f71cd29529edb5244e
- File type: script · Size: 307762 bytes
- Verdict: suspicious (54/100)
Detections (3 of 53 engines)
- Microsoft Defender: Trojan:JS/HideLink.A
- Emsisoft (Emergency Kit): Trojan.JS.HideLink.F
- Kaspersky (KVRT): HEUR:Trojan.JS.Infect.gen
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (layers: base64+concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://flowplayer.com/e/, https://flowplayer.com/s/, https://twitter.com/intent/tweet?url= - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://www.gstatic.com/cv/js/sender/v1/cast_sender.js
- https://flowplayer.com/e/
- https://flowplayer.com/s/
- http://www.w3.org/2000/svg
- https://twitter.com/intent/tweet?url=
- http://get.adobe.com/flashplayer/
- https://flowplayer.com/hello/?from=player
- https://flowplayer.com/license
- http://cherne.net/brian/resources/jquery.hoverIntent.html
- http://gsgd.co.uk/sandbox/jquery/easing/
- http://www.opensource.org/licenses/mit-license.php
- http://www.gnu.org/licenses/gpl.html
- http://www.designchemical.com
- http://joshualavigne.com/wp-content/plugins/slick-contact-forms/js/jquery.slick.contact.1.3.2.js
Embedded domains
- s.w.org
- joshualavigne.com
- schema.org
- flowplayer.com
- t.top
- e.conf.live
- e.live
- r.live
- t.live
- e.name
- google-analytics.com
- www.gstatic.com
- www.facebook.com
- n.live
- finish.pl
- unload.pl
- www.w3.org
- twitter.com
- t.conf.live
- p.live
- window.top
- releases.flowplayer.org
- get.adobe.com
- flowplayer.org
- this.name
File paths
- d:\d\d:\d\d
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report