MALICIOUS — 03a97fc05a8b29c7875d0624e501c93d2142b1441bf65ffd4ef135926633c5ff
MALICIOUS — 03a97fc05a8b29c7875d0624e501c93d2142b1441bf65ffd4ef135926633c5ff is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100), attributed to the Acsogenixx family. 1 of 23 detection engines flagged it.
Identification
- SHA-256:
03a97fc05a8b29c7875d0624e501c93d2142b1441bf65ffd4ef135926633c5ff - SHA-1:
be837758c667dc05e3a3150e6deece30538f140a - MD5:
666fec69c389bf067caec56208b48962 - ssdeep:
384:6YzPZ9zHBqld6rTyv6Rb+nQKrlibQmYMH/pMF1E:BzL8gyvCAdhi8yfpe1E - TLSH:
T143253A292BF51A8FD5809703F82894BC25F6E3EFD9351697021AEF8E4408DF2A41D19D - Submitted as: 03a97fc05a8b29c7875d0624e501c93d2142b1441bf65ffd4ef135926633c5ff
- File type: html · Size: 13283 bytes
- Verdict: malicious (75/100) · Family: Acsogenixx
Detections (1 of 23 engines)
- Emsisoft (Emergency Kit): GT:JS.Acsogenixx.10.88DE4F5B
Why this verdict
The malicious score of 75/100 is the fusion of 3 weighted signals:
- Emsisoft (Emergency Kit) flagged GT:JS.Acsogenixx.10.88DE4F5B (rule
GT:JS.Acsogenixx.10.88DE4F5B) - engine signal, weight 0.55, confidence 0.85 - Obfuscated powershell script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://secure.aadcdn.microsoftonline-p.com/ests/2.1.8148.16/content/images/microsoft_logo.png?x=ed9c9eb0dce17d752bedea6b5acda6d9, https://secure.aadcdn.microsoftonline-p.com/ests/2.1.8148.16/content/images/microsoft_logo.svg?x=ee5c8d9fb6248c938fd0dc19370e90bd - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://secure.aadcdn.microsoftonline-p.com/ests/2.1.8148.16/content/images/microsoft_logo.png?x=ed9c9eb0dce17d752bedea6b5acda6d9
- https://secure.aadcdn.microsoftonline-p.com/ests/2.1.8148.16/content/images/microsoft_logo.svg?x=ee5c8d9fb6248c938fd0dc19370e90bd
- https://fonts.gstatic.com/s/opensans/v16/mem5YaGs126MiZpBA-UN_r8OUuhs.ttf
Embedded domains
- secure.aadcdn.microsoftonline-p.com
- fonts.gstatic.com
- s.to
More Acsogenixx samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report