MALICIOUS — c5510b067dac6e4cff91a5cf3a3200b3114146c5e7a2260c03d69449ca667c4e
MALICIOUS — c5510b067dac6e4cff91a5cf3a3200b3114146c5e7a2260c03d69449ca667c4e is a script sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the PowerShell family. 4 of 51 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
c5510b067dac6e4cff91a5cf3a3200b3114146c5e7a2260c03d69449ca667c4e - SHA-1:
36cba6a620e1899c2adbd46ac2d5af389f27421d - MD5:
5d7acbed450c662042b624da2c6b74e0 - ssdeep:
24:iqHMBqR87lUY2AhnmgEhDBkskalEC/KcEC1SA3P9CW81c0nBpjWU:nHMBqR8yY1hn5VUEYKSpU1VBpSU - TLSH:
T1711311B82E5105914191737548B121C2C860AE4D0CD5B6A3A7C3F1AA2E72B33AA09BD2 - Submitted as: c5510b067dac6e4cff91a5cf3a3200b3114146c5e7a2260c03d69449ca667c4e
- File type: script · Size: 1228 bytes
- Verdict: malicious (99/100) · Family: PowerShell
Detections (4 of 51 engines)
- YARA: MalwareAnalyser built-in: Suspicious_PowerShell_Download_Exec
- capa (capabilities): execute via PowerShell
- YARA: MalwareAnalyser community pack: TL_Base64_EncodedCommand
- Kaspersky (KVRT): HEUR:Trojan.PowerShell.Generic
MITRE ATT&CK
YARA
- Suspicious_PowerShell_Download_Exec
Why this verdict
The malicious score of 99/100 is the fusion of 10 weighted signals:
- Encoded/hidden PowerShell download-and-exec (rule
Suspicious_PowerShell_Download_Exec) - yara signal, weight 0.70, confidence 0.90 - 1 behavioral detection(s): Download-and-execute dropper (wget/curl + chmod) [high] (rule
tl-linux-download-exec) - dynamic signal, weight 0.60, confidence 0.90 - 1 behavioral detection(s): Download-and-execute dropper (wget/curl + chmod) [high] (rule
tl-linux-download-exec) - dynamic signal, weight 0.60, confidence 0.90 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - Anti-analysis: T1497 - dynamic signal, weight 0.40, confidence 0.75
- Anti-analysis: T1497 - dynamic signal, weight 0.40, confidence 0.75
- Obfuscated powershell script: hidden-window (rule
script-deobfuscation) - static signal, weight 0.35, confidence 0.75 - YARA: MalwareAnalyser community pack flagged TL_Base64_EncodedCommand (rule
TL_Base64_EncodedCommand) - engine signal, weight 0.35, confidence 0.70 - Contacted 9 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Contacted 9 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (linux)
860 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- entropy.ubuntu.com
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- 185.125.189.53:443
- ff02::1:3
- 224.0.0.252
- 185.125.189.53
- 10.240.0.1
- 185.125.189.52
- 185.125.189.54
- 10.240.0.255
- ff02::fb
- 224.0.0.251
- ff02::1:ff12:3456
- ff02::16
Dropped files
- tmp_tmp.VWr5hVll6a -
68c0f945cb7fb35cb65822c407bfb4eba3f1f40b3df16c9c60c12b653e696fb2
Embedded IP addresses
- 20.165.94.63
- 20.42.179.204
- 20.184.175.9
More PowerShell samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report