MALICIOUS — 11bf2897f7b570ae4bdda6b54c83746107b76826934a5854921d3766c325f0af
MALICIOUS — 11bf2897f7b570ae4bdda6b54c83746107b76826934a5854921d3766c325f0af is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (91/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
11bf2897f7b570ae4bdda6b54c83746107b76826934a5854921d3766c325f0af - SHA-1:
3d15daccd1ba503ccb10f3c69a4a0e27e4699b16 - MD5:
596b683a7937fc21eda9514741cdd0e7 - ssdeep:
384:FhQs0RWRTRhORtRhORTRhORhOR5RhORhORhORwR5RwR5RdRmRhORWRdRHRmRwRkM:F - TLSH:
T1AB2AAEB65AB2131A7644F88311AD9C91D04BAC7D2F633797AEE4970248CC3A684FD335 - Submitted as: 11bf2897f7b570ae4bdda6b54c83746107b76826934a5854921d3766c325f0af
- File type: html · Size: 20410 bytes
- Verdict: malicious (91/100)
Detections (2 of 53 engines)
- ClamAV (daily): Win.Trojan.JS-237
- Kaspersky (KVRT): HEUR:Trojan-Downloader.Script.Generic
Why this verdict
The malicious score of 91/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Trojan.JS-237 (rule
Win.Trojan.JS-237) - engine signal, weight 0.90, confidence 0.95 - Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- jamesdurr.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report