SUSPICIOUS — 11b0878beb3d68a055e1a33c72b7ed772df8a09e180c1d323f5e2809449fa903
SUSPICIOUS — 11b0878beb3d68a055e1a33c72b7ed772df8a09e180c1d323f5e2809449fa903 is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
11b0878beb3d68a055e1a33c72b7ed772df8a09e180c1d323f5e2809449fa903 - SHA-1:
19d10ec1f269bc889867c210f52b9b1109bbb6a1 - MD5:
e6f5a65e0135aebb4df1f625a8d2ca4d - ssdeep:
192:qulMHKzNoFijcFf2E94Vu8fBlGQes/eUeK2lQoEepe0EeAeVenlOD2s:rOHKzNoL2E94VuIBlGQes/eUeKgEepei - TLSH:
T11722C81253A5BFDE94C4404A915828ACE0C6FB9B4A267CF5C3ACDF521C098B1F4DE197 - Submitted as: 11b0878beb3d68a055e1a33c72b7ed772df8a09e180c1d323f5e2809449fa903
- File type: html · Size: 9984 bytes
- Verdict: suspicious (54/100)
Detections (2 of 53 engines)
- Microsoft Defender: Trojan:HTML/MinerQ!rfn
- Kaspersky (KVRT): HEUR:Trojan.JS.Miner.gen
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://www.subBlue.com/, http://www.phpbb.com, http://milky-mansion.space-forums.com/215-f96.html - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd
- http://www.w3.org/1999/xhtml
- http://www.subBlue.com/
- http://www.phpbb.com
- http://milky-mansion.space-forums.com/215-f96.html
- http://partner.googleadservices.com/gampad/google_service.js
- http://semi.phpbbmodders.net/
- http://www.space-forums.com
- http://www.space-blogs.com
- http://www.mon-blog.net
- http://www.blogolink.com
- http://script.affilizr.com/js/affilizr.js
- http://www.phpbb.com/
Embedded domains
- www.w3.org
- phpbbmodders.net
- www.phpbb.com
- milky-mansion.space-forums.com
- space-forums.com
- stats.g.doubleclick.net
- partner.googleadservices.com
- semi.phpbbmodders.net
- www.space-forums.com
- www.space-blogs.com
- www.mon-blog.net
- www.blogolink.com
- script.affilizr.com
- www.subblue.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report