MALICIOUS — HTML.NoMercy.b.html
MALICIOUS — HTML.NoMercy.b.html is a hta sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100), attributed to the NMVT family. 2 of 49 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
06b5631ccb3596938806099a550e09f724816dd45cfe43ef9cbd5d1d1f4063e1 - SHA-1:
cf8151f692e89f92565745f04fe1210e1583af17 - MD5:
54d7a0c80595ec07cfe9c9da6cceec26 - ssdeep:
96:9ehcpRyLzz5Q0BxzYgD5QSffapAPgKc4z48wGjGT:9eypEm0wOxCUw/T - TLSH:
T1F31A827C5A64B9AF9C4F63E7C52E0EF8812C28C3A0427A20E0DC669220197F51D9D85F - Submitted as: HTML.NoMercy.b.html
- File type: hta · Size: 4756 bytes
- Verdict: malicious (94/100) · Family: NMVT
Detections (2 of 49 engines)
- Microsoft Defender: Virus:VBS/NMVT.B
- Emsisoft (Emergency Kit): VBS.NMVT.B
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 7 weighted signals:
- 1 behavioral detection(s): LOLBin: mshta executing remote/scripted payload [high] (rule
tl-lolbin-mshta) - dynamic signal, weight 0.60, confidence 0.90 - Microsoft Defender flagged Virus:VBS/NMVT.B (rule
Virus:VBS/NMVT.B) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged VBS.NMVT.B (rule
VBS.NMVT.B) - engine signal, weight 0.55, confidence 0.85 - Document contains macros/active content: create-object, wscript-shell - static signal, weight 0.35, confidence 0.75
- Embedded network infrastructure: http://www.webtv.com, http://sourceofkaos.com/homes/nomercy - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (2 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1642 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- searchapp.bundleassets.example
- www.msftconnecttest.com
- config.edge.skype.com
- desktop-hsgcbep
- www.bing.com
- watson.events.data.microsoft.com
- g.live.com
- dns.msftncsi.com
- self.events.data.microsoft.com
- edge.microsoft.com
- aefd.nelreports.net
- www.msftncsi.com
- settings-win.data.microsoft.com
- time.windows.com
- licensing.mp.microsoft.com
- tsfe.trafficshaping.dsp.mp.microsoft.com
- geo.prod.do.dsp.mp.microsoft.com
- 192.168.122.107
- 192.168.122.255
- 192.168.122.1
Embedded URLs
- http://www.webtv.com
- http://sourceofkaos.com/homes/nomercy
Embedded domains
- www.webtv.com
- sourceofkaos.com
- target.name
- aefd.nelreports.net
Registry keys
- HKEY_LOCAL_MACHINE\Infected\With\Name
- HKEY_LOCAL_MACHINE\Infected\With\Author
- HKEY_LOCAL_MACHINE\Infected\With\Team
- HKEY_LOCAL_MACHINE\Infected\With\URL
File paths
- C:\temp
- C:\My
- C:\Windows\Desktop
- C:\Windows\Web
- C:\Windows\Web\Wallpaper
- C:\Windows\Help
- C:\Windows\Temp
- C:\Windows\ShellNew
- C:\Windows\System
- C:\Windows
- C:\Winnt\Desktop
- C:\Winnt\Web
- C:\Winnt\Web\Wallpaper
- C:\Winnt\Help
- C:\Winnt\Temp
- C:\Winnt\ShellNew
- C:\Winnt\System
- C:\Winnt
- C:\Program
- C:\Inetpub\wwwroot
- C:\Inetpub\wwwroot\myweb
- C:\webshare\wwwroot
- C:\webshare\wwwroot\myweb
More NMVT samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report