SUSPICIOUS — 1106169325921a81d33e336a80d813ca698aee1e32e26b42c8cb9493f1dea2ae
SUSPICIOUS — 1106169325921a81d33e336a80d813ca698aee1e32e26b42c8cb9493f1dea2ae is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (59/100). 3 of 23 detection engines flagged it.
Identification
- SHA-256:
1106169325921a81d33e336a80d813ca698aee1e32e26b42c8cb9493f1dea2ae - SHA-1:
6a432dfedce06bf792e08e6c5dc3f6b5a3f5c8d7 - MD5:
c2aa04926b0d9abe04153d6bd72be02f - File type: script · Size: 278506 bytes
- Verdict: suspicious (59/100)
Detections (3 of 23 engines)
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
- Microsoft Defender: Trojan:JS/Agent.AG!MSR
- Emsisoft (Emergency Kit): GT:JS.Injected.1.9FD4112E
Dynamic analysis (linux)
843 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- desktop-hsgcbep
- 10.240.0.1
- 224.0.0.251
- ff02::fb
- ff02::1:3
- 224.0.0.252
- 57.155.101.212 SG · Singapore · AS8075 Microsoft Limited UK
- 72.154.7.101 US · Moses Lake · AS8075 Microsoft Corporation
- 172.215.188.225 US · San Antonio · AS8075 Microsoft Limited
- 135.232.92.34 US · Boydton · AS8075 Microsoft Limited
- 255.255.255.255
- 91.189.91.157
- ff02::16
- 169.254.255.255
- 224.0.0.22
- ff02::1
- ff02::2
- ff02::1:2
Dropped files
- tmp_tmp.tdWgW6tbDN —
c097dd91488dec9367d2737f1b0ab0674875af73456d89b1faca0503ad32c47f
Embedded URLs
- http://www.w3.org/2000/svg
- https://feedburner.google.com/fb/a/mailverify?uri=
- http://www.hulu.com
- http://www.dailymotion.com
- http://www.funnyordie.com
- https://embed-ssl.ted.com
- http://embed.revision3.com
- https://flickr.com
- http://blip.tv
- http://www.collegehumor.com
- http://css-tricks.com
- http://daverupert.com
- http://www.alistapart.com/articles/creating-intrinsic-ratios-for-video/
- http://sam.zoy.org/wtfpl/
Embedded domains
- jquery.org
- window.top
- n.top
- this.name
- t.name
- www.w3.org
- offsets.top
- e.top
- e.name
- c.top
- c.top-p.top
- f.top-u.top
- d.top
- feedburner.google.com
- www.hulu.com
- www.dailymotion.com
- www.funnyordie.com
- embed-ssl.ted.com
- embed.revision3.com
- flickr.com
- blip.tv
- www.collegehumor.com
- l.top
- t.top
- n-t.top
Embedded IP addresses
- 57.155.101.212
- 72.154.7.101
- 172.215.188.225
- 135.232.92.34
- 20.165.94.63
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report