SUSPICIOUS — 11ba7aef120b9edc2b40484073f99e9baf34511221bb704d580059a5abf94c7b
SUSPICIOUS — 11ba7aef120b9edc2b40484073f99e9baf34511221bb704d580059a5abf94c7b is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
11ba7aef120b9edc2b40484073f99e9baf34511221bb704d580059a5abf94c7b - SHA-1:
0f159afa386b34ace203d84cda8040671d42a13d - MD5:
454dfe25e00150580789ef84039d7485 - ssdeep:
1536:AykADkAZckABKQbZkAXhTcr0KPGNMxZPdJXxPTQakA5fLAvFSrME4zNL4cxNL4cc:dkADkAikAIGZkARTcr0QGNMxZPdJXxPB - TLSH:
T181350A5BF622774B8DF0511116AD27D514CBC227A92363E5D9DBEF888C2CC217C8C46A - Submitted as: 11ba7aef120b9edc2b40484073f99e9baf34511221bb704d580059a5abf94c7b
- File type: html · Size: 57577 bytes
- Verdict: suspicious (54/100)
Detections (2 of 53 engines)
- Microsoft Defender: TrojanClicker:JS/Faceliker.M
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1667664774-css_bundle_v2.css, http://s.haivl.com/content/images/logo_smiley.jpg, http://s.haivl.com/content/images/logo_40.png - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.google.com/2005/gml/b
- http://www.google.com/2005/gml/data
- http://www.google.com/2005/gml/expr
- https://www.blogger.com/static/v1/widgets/1667664774-css_bundle_v2.css
- http://thuymien.com/wp-content/uploads/2013/06/favicon.ico
- https://plus.google.com/106109000175979615274/about
- https://plus.google.com/106109000175979615274/posts
- http://s.haivl.com/content/images/logo_smiley.jpg
- http://s.haivl.com/content/images/logo_40.png
- http://s.haivl.com/content/images/upload_icon.png
- http://s.haivl.com/content/images/down_icon.png
- http://s.haivl.com/content/images/admin/icons/exclamation.png
- http://s.haivl.com/content/images/admin/icons/information.png
- http://s.haivl.com/content/images/admin/icons/tick_circle.png
- http://s.haivl.com/content/images/admin/icons/cross_circle.png
- http://s.haivl.com/content/images/admin/icons/cross_grey_small.png
- http://s.haivl.com/content/images/vote_icon.png
- http://s.haivl.com/content/images/view_icon.png
- http://s.haivl.com/content/images/comment_icon.png
- http://s.haivl.com/content/images/source_icon.png
- http://s.haivl.com/content/images/like_icon.png
- http://s.haivl.com/content/images/smile_icon.png
- http://s.haivl.com/content/images/prev_icon.png
- http://s.haivl.com/content/images/next_icon.png
Embedded domains
- www.w3.org
- www.google.com
- www.blogger.com
- thuymien.com
- djdownload.biz
- plus.google.com
- s.haivl.com
- www.facebook.com
- blogspot.com
- pornpicsalbum.blogspot.com
- twitter.com
- platform.twitter.com
- widgets.amung.us
- img1.blogblog.com
- lh3.ggpht.com
- 4.bp.blogspot.com
- 3.bp.blogspot.com
- 2.bp.blogspot.com
- lh6.ggpht.com
- lh5.ggpht.com
- disqus.com
- vert.top
- cdn.firebase.com
- vuime.firebaseio.com
- www.blogblog.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report