SUSPICIOUS — f3a91608f3336e83a2227b52afff45f9ec390a3145032052a4cbbb5ca1a3de3c
SUSPICIOUS — f3a91608f3336e83a2227b52afff45f9ec390a3145032052a4cbbb5ca1a3de3c is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
f3a91608f3336e83a2227b52afff45f9ec390a3145032052a4cbbb5ca1a3de3c - SHA-1:
c7c435b5e656280eaddb8fcba34800ae10a251a4 - MD5:
7deb983069f3d67a72310278c709a9dc - ssdeep:
1536:tjaxl8yra469QduD5VFg2WKl+2qCd+m0SNpINVp7Nu1HfwvoOdV3LU6AKS5P:N469QstWKALm0SbI7u5WogbpcP - TLSH:
T1583C3ABB394F3D9CCC0EA04B3D9D7E9B73039A18B3E290D592EDCB4564AACC11819465 - Submitted as: f3a91608f3336e83a2227b52afff45f9ec390a3145032052a4cbbb5ca1a3de3c
- File type: script · Size: 121175 bytes
- Verdict: suspicious (54/100)
Detections (2 of 50 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (layers: char-code) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://labs.rampinteractive.co.uk/touchSwipe/, http://plugins.jquery.com/project/touchSwipe, https://greensock.com - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.github.com/mattbryson
- https://github.com/mattbryson/TouchSwipe-Jquery-Plugin
- http://labs.rampinteractive.co.uk/touchSwipe/
- http://plugins.jquery.com/project/touchSwipe
- https://greensock.com
- https://greensock.com/standard-license
- http://www.w3.org/1999/xhtml
- http://www.w3.org/2000/svg
Embedded domains
- www.github.com
- github.com
- labs.rampinteractive.co.uk
- plugins.jquery.com
- m.top
- g.top
- greensock.com
- t.name
- n.to
- o.to
- e.to
- sn.to
- www.w3.org
- s.top-u.top
- a.top-u.top
- u.top
- this.ru
- e.ru
- n.top-i.top
- d.top
- g.style.top
- h.style.top
- sebooconsulting.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report