SUSPICIOUS — classic.js
SUSPICIOUS — classic.js is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (59/100). 0 of 50 detection engines flagged it.
Identification
- SHA-256:
f9ccdaa68ad30b653358a8e0f980095c3bef97aa441213ad7aaa34d004485085 - SHA-1:
1509a56e9be4e0102365108dd087e3ea36c87401 - MD5:
2fb433c4e90d799207f463c0d2ac54bb - ssdeep:
192:GiPMBjPBm8N3Ch+bad6573T9C2riNRk6NLHuRJO4MUrC9Bri9L7hVPhCC3V:GiPMBPBmGDad495iDL0L1MUrC9Bri9LB - TLSH:
T180235C32BA15BDCCCC0E3401DEC43A9A3F5770219A7A51F4ECFCDBA178589751418866 - Submitted as: classic.js
- File type: script · Size: 11154 bytes
- Verdict: suspicious (59/100)
Detections (0 of 50 engines)
No engine flagged this sample.
Why this verdict
The suspicious score of 59/100 is the fusion of 4 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://whos.amung.us/stats/, https://t.dtscout.com/i/?l= - static signal, weight 0.35, confidence 0.60
- Contacted 6 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (2 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
843 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- desktop-hsgcbep
- 10.240.0.1
- 224.0.0.251
- ff02::fb
- ff02::1:3
- 224.0.0.252
- ff02::16
- 10.240.0.255
- 224.0.0.22
- 74.178.240.61 NL · Amsterdam · AS8075 Microsoft Corporation
- ff02::1
- ff02::1:ff12:3456
- 185.125.190.57
- 255.255.255.255
- 52.123.252.193 AU · Sydney · AS8075 Microsoft Corporation
- 185.125.190.56
- ff02::2
- 52.123.252.222 AU · Sydney · AS8075 Microsoft Corporation
Dropped files
- tmp_tmp.lVTpWsDZra -
8e1f6dbc5418d7aef5aaccbbb87e82f6ad6f7b93f6a730e888f343c7c665a8ee
Embedded URLs
- https://whos.amung.us/stats/
- https://t.dtscout.com/i/?l=
Embedded domains
- whos.amung.us
- widgets.amung.us
- t.style.top
- amung.us
- t.dtscout.com
Embedded IP addresses
- 74.178.240.61
- 52.123.252.193
- 52.123.252.222
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report