SUSPICIOUS — main_menu.js
SUSPICIOUS — main_menu.js is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (45/100). 0 of 51 detection engines flagged it.
Identification
- SHA-256:
ec44bf9b374a9477850a6f65ff1b0f1b92574664653e31717aafa46eb0bc9ede - SHA-1:
26ad44db6af6f6b083afe3bff7ae004fedb65db0 - MD5:
2e0bffa5f90ad18c327f695c5bddbd2b - ssdeep:
48:fTEei6DzVsSjT/IfiHgSk2jFespWLp55pRLKpjLPsptv9DzrTy0gFe1VVpsprpR4:aY3SdFIFe83wqYnCU - TLSH:
T140168F0C613FED8E052E8ACF64784452C438619CDA2229419BD1BE13F8A6F38F556B1F - Submitted as: main_menu.js
- File type: script · Size: 3098 bytes
- Verdict: suspicious (45/100)
Detections (0 of 51 engines)
No engine flagged this sample.
Why this verdict
The suspicious score of 45/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 9 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (linux)
868 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- _dosvc._tcp.local
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- 224.0.0.251
- ff02::fb
- ff02::1:3
- 224.0.0.252
- 10.240.0.1
- ff02::1
- ff02::16
- ff02::2
- ff02::1:ff4c:1d1d
- 48.211.4.16 US · Ashburn · AS8075 Microsoft Limited
- ff02::1:ff12:3456
- 91.189.91.157
- 239.255.255.250
- ff02::1:2
- 224.0.0.22
Dropped files
- tmp_tmp.7LaERCvO0C -
2063460cf56f42b3a865a690c79e1f758339c41620eff7d3e4f5946eade15179
Embedded IP addresses
- 48.211.4.16
- 51.11.192.49
- 20.190.167.150
- 203.26.79.13
- 57.155.104.224
- 20.42.65.94
- 4.150.223.105
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report