SUSPICIOUS — 11b0a94a4329eb77e29e5784fb41f5ecfad572709450fec237bb8b308ada1cdc
SUSPICIOUS — 11b0a94a4329eb77e29e5784fb41f5ecfad572709450fec237bb8b308ada1cdc is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 1 of 53 detection engines flagged it.
Identification
- SHA-256:
11b0a94a4329eb77e29e5784fb41f5ecfad572709450fec237bb8b308ada1cdc - SHA-1:
8061a5807f428af36baa11692e72b6179f33592d - MD5:
937c3ade0e422ad16947decc2aa578dc - ssdeep:
768:4BQpcVCWG95w7bwv/aH9DTxq2lh81tqbDq4Niw7H0F2yb98b:4BQpp595w7bwv/WSehAtqbDq4j7H00 - TLSH:
T11B35C517A1592F9210F069317D8D0658A0DEE6DFEB7B91E1C212D9C8FC7C850E865C8B - Submitted as: 11b0a94a4329eb77e29e5784fb41f5ecfad572709450fec237bb8b308ada1cdc
- File type: html · Size: 62500 bytes
- Verdict: suspicious (54/100)
Detections (1 of 53 engines)
- Microsoft Defender: Trojan:HTML/Scrinject.C!bit
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css, https://khmer-unicode-ios-andriods.blogspot.com/favicon.ico, https://khmer-unicode-ios-andriods.blogspot.com/feeds/posts/default - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css
- https://khmer-unicode-ios-andriods.blogspot.com/favicon.ico
- http://khmer-unicode-ios-andriods.blogspot.com/2014/01/samsung-galaxy-note-ii-gt-n7100.html
- https://khmer-unicode-ios-andriods.blogspot.com/feeds/posts/default
- https://khmer-unicode-ios-andriods.blogspot.com/feeds/posts/default?alt=rss
- https://www.blogger.com/feeds/3763054390910767539/posts/default
- https://khmer-unicode-ios-andriods.blogspot.com/feeds/3315776404543269966/comments/default
- http://3.bp.blogspot.com/-HJsbTJPD7gM/Uui7k0JffyI/AAAAAAAABBI/i-Kbs97jKxc/s1600/Screenshot_2013-11-17-12-35-50.png
- https://ajax.googleapis.com/ajax/libs/jquery/1.5.1/jquery.min.js
- http://www.templateify.com
- https://ajax.googleapis.com/ajax/libs/jquery/1.8.3/jquery.min.js
- https://www.blogger.com/dyn-css/authorization.css?targetBlogID=3763054390910767539&
- http://khmer-unicode-ios-andriods.blogspot.com/2014/06/room-fixed-all-andriods-menukhmer.html
- http://khmer-unicode-ios-andriods.blogspot.com/search/label/Unicode%20khmer%20Samsung
- http://prsphone.com/
- http://font-cambodia.blogspot.com/
- https://khmer-unicode-ios-andriods.blogspot.com/
- http://new-facebook-tipstricks.blogspot.com/
- http://khmer-unicode-ios-andriods.blogspot.com/search/label/Firmware%20IOS
- http://khmer-unicode-ios-andriods.blogspot.com/search/label/Firmware%20Sony%20Ericsson
- http://khmer-unicode-ios-andriods.blogspot.com/search/label/Firmware%20Samsung
- http://khmer-unicode-ios-andriods.blogspot.com/search/label/Firmware%20LG
- http://khmer-unicode-ios-andriods.blogspot.com/search/label/Firmware%20SKY%20IM%20%28Stock%20Room%29
- http://khmer-unicode-ios-andriods.blogspot.com/search/label/Unicode%20khmer%20LG
- http://khmer-unicode-ios-andriods.blogspot.com/search/label/Game%20PC
Embedded domains
- www.blogger.com
- khmer-unicode-ios-andriods.blogspot.com
- 3.bp.blogspot.com
- fonts.googleapis.com
- ajax.googleapis.com
- googledrive.com
- www.templateify.com
- templateify.com
- blogspot.com
- prsphone.com
- font-cambodia.blogspot.com
- 4.bp.blogspot.com
- www.facebook.com
- new-facebook-tipstricks.blogspot.com
- schema.org
- terafile.co
- 2.bp.blogspot.com
- lh6.googleusercontent.com
- d.link
- static.ak.fbcdn.net
- 1.bp.blogspot.com
- 24work.blogspot.com
- bitly.com
- safir85.ucoz.com
- apis.google.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report