SUSPICIOUS — f1cbe5f24bb5373e39fa3abb363f16cfa5f9bf3475bc1e8cdef239051a3fa310
SUSPICIOUS — f1cbe5f24bb5373e39fa3abb363f16cfa5f9bf3475bc1e8cdef239051a3fa310 is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (65/100), attributed to the Gootloader family. 3 of 53 detection engines flagged it.
Identification
- SHA-256:
f1cbe5f24bb5373e39fa3abb363f16cfa5f9bf3475bc1e8cdef239051a3fa310 - SHA-1:
3c7374b52b773ad44345778c91570029410c9782 - MD5:
700fc45843338fe6d81e96158d6dee42 - ssdeep:
6144:iTGCILt1TZsic6Yz7507ULd1RLXZE59RnyFaLue/EQN/UJHlFDf39g4S1TqwOJrO:iTG3lo6e0ktXZO9lyFnQbD - TLSH:
T1EE4AE86B37E87CDF954A49E6298C252EB4131ED3350314E0C6A8EF859C9FF61242C46B - Submitted as: f1cbe5f24bb5373e39fa3abb363f16cfa5f9bf3475bc1e8cdef239051a3fa310
- File type: script · Size: 457528 bytes
- Verdict: suspicious (65/100) · Family: Gootloader
Detections (3 of 53 engines)
- YARA: SophosLabs IoCs (public): SOPHOS_Gootloader_JS
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 65/100 is the fusion of 3 weighted signals:
- Obfuscated powershell script: dynamic-exec, defense-evasion (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - YARA: SophosLabs IoCs (public) flagged SOPHOS_Gootloader_JS (rule
SOPHOS_Gootloader_JS) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://quirksmode.org/mobile/tableViewport.html, https://api.jquery.com/jquery.getscript/, http://bugs.jquery.com/ticket/13393 - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
1151 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- c.pki.goog
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 255.255.254.169.in-addr.arpa
- 79.243.254.169.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- desktop-hsgcbep
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
Embedded URLs
- https://github.com/marcj/css-element-queries/blob/master/LICENSE
- https://github.com/Mr0grog/element-query/blob/master/LICENSE
- http://quirksmode.org/mobile/tableViewport.html
- https://api.jquery.com/jquery.getscript/
- http://www.vrdmn.com/2013/07/overriding-jquerygetscript-to-include.html
- https://github.com/sdecima/javascript-detect-element-resize
- https://code.google.com/p/chromium/issues/detail?id=286360
- http://bugs.jquery.com/ticket/13393
- https://github.com/jquery/jquery/commit/85fc5878b3c6af73f42d61eedf73013e7faae408
- http://www.abeautifulsite.net/detecting-mobile-devices-with-javascript/
- http://gsgd.co.uk/sandbox/jquery/easing/
- http://www.youtube.com/watch?v=opj24KnzrWo
- http://www.youtube.com/embed/opj24KnzrWo
- http://youtu.be/opj24KnzrWo
- http://www.youtube-nocookie.com/embed/opj24KnzrWo
- http://vimeo.com/40648169
- http://vimeo.com/channels/staffpicks/38843628
- http://vimeo.com/groups/surrealism/videos/36516384
- http://player.vimeo.com/video/45074303
- http://www.metacafe.com/watch/7635964/dr_seuss_the_lorax_movie_trailer/
- http://www.metacafe.com/watch/7635964/
- http://www.dailymotion.com/video/xoytqh_dr-seuss-the-lorax-premiere_people
- http://twitvid.com/QY7MD
- http://twitpic.com/7p93st
- http://instagr.am/p/IejkuUGxQn/
Embedded domains
- github.com
- quirksmode.org
- api.jquery.com
- www.vrdmn.com
- code.google.com
- bugs.jquery.com
- www.abeautifulsite.net
- apachemobilefilter.org
- detectright.com
- web.wurfl.io
- hgoebl.github.io
- video.style.top
- rect.top
- gsgd.co.uk
- fancyapps.com
- c.top
- a.live
- www.youtube.com
- youtu.be
- www.youtube-nocookie.com
- vimeo.com
- player.vimeo.com
- www.metacafe.com
- www.dailymotion.com
- twitvid.com
Embedded IP addresses
- 4.150.223.97
- 52.182.141.63
- 172.66.2.5
- 52.110.12.47
- 74.179.77.204
- 4.230.171.124
- 20.42.179.192
- 135.233.95.135
- 20.112.250.133
- 52.123.128.14
- 52.123.252.230
- 20.165.94.46
- 203.26.79.13
- 13.89.179.12
- 172.217.25.195
- 172.215.188.232
- 135.234.160.244
- 172.175.111.170
- 162.159.36.2
More Gootloader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report