SUSPICIOUS — 3903731066-lbx__pt_br.js
SUSPICIOUS — 3903731066-lbx__pt_br.js is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 0 of 50 detection engines flagged it.
Identification
- SHA-256:
f7e2bc3ee0d4f9ae4d1267999a73f2e2ec26ef7e3a097f08325687a6e154037d - SHA-1:
9592674d3d1e30886a3133cb557b57d4872369bb - MD5:
a0f326c861cd58ff323cdebbb625082b - ssdeep:
3072:4b/cCUdFd9b9jvJKLQt0FM89C15kJCnA7wCSUcuww/qZCUqWvees/vnvgaL+T428:4bl6Dlvdt0Fw1xCShw2tNSP+T42Do - TLSH:
T1FC4873DE3986AEDECC0E30AE7E4C64A3B7039E5476B690E082BDD36554E1CD03DA8415 - Submitted as: 3903731066-lbx__pt_br.js
- File type: script · Size: 365906 bytes
- Verdict: suspicious (54/100)
Detections (0 of 50 engines)
No engine flagged this sample.
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated powershell script: dynamic-exec, defense-evasion (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://flickr.com/photos/, 2.0.0.11 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://photos.google.com/lightbox/photoid
- http://flickr.com/photos/
- http://picasaweb.google.com/
- http://google.com/profiles/media/container
- http://google.com/profiles/media/provider
- http://www.google.com/intl/
Embedded domains
- photos.google.com
- a.ga
- ee.prototype.name
- this.se
- a.se
- this.it
- a.it
- a.ai
- this.ai
- this.ml
- r.ml
- this.sg
- a.sg
- r.eu
- this.nl
- this.fi
- this.uk
- g.fi
- a.fi
- c.uk
- this.be
- this.mx
- this.ua
- h.name
- this.co
Embedded IP addresses
- 2.0.0.11
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report