SUSPICIOUS — fb17303d9ff2f65626155051a193940b0fd1c717d1ba8a9074a0b2d94f1eea6a
SUSPICIOUS — fb17303d9ff2f65626155051a193940b0fd1c717d1ba8a9074a0b2d94f1eea6a is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
fb17303d9ff2f65626155051a193940b0fd1c717d1ba8a9074a0b2d94f1eea6a - SHA-1:
6732f03886e4960dba4485febc46c778c6114a60 - MD5:
4e26b8d0c4950913b02a06902a2250db - ssdeep:
384:ufvahQLuJz+KpEXIFK19WG4r1ziMKPsqu:K7IE9W1x/Jqu - TLSH:
T1D829E99F78CF2DADCC0E81573DCEB957770BAA257242A0C441ADCF8958E1DE41C89429 - Submitted as: fb17303d9ff2f65626155051a193940b0fd1c717d1ba8a9074a0b2d94f1eea6a
- File type: script · Size: 18722 bytes
- Verdict: suspicious (54/100)
Detections (2 of 53 engines)
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://jqueryui.com, http://jquery.org/license - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://jqueryui.com
- http://jquery.org/license
- https://github.com/jquery/jquery-color
Embedded domains
- jqueryui.com
- jquery.org
- e.space
- github.com
- n.to
- e.to
- g.hsla.to
- t.to
- t.clip.bottom-t.clip.top
- t.clip.top
- r.top
- t.top
- o.top
- t.end.top-t.start.top
- t.start.top
- edenroc.biz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report