MALICIOUS — 12ec07adae3a921b1d5b3579019bb34eb0a9b3354070d6ecfd90a72c7f7de4bf
MALICIOUS — 12ec07adae3a921b1d5b3579019bb34eb0a9b3354070d6ecfd90a72c7f7de4bf is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 2 of 54 detection engines flagged it.
Identification
- SHA-256:
12ec07adae3a921b1d5b3579019bb34eb0a9b3354070d6ecfd90a72c7f7de4bf - SHA-1:
e9e901e4f053ca419a754613acaba99478664887 - MD5:
e23fc9a5b9cf7a9b249bab258aa59814 - ssdeep:
3072:XBvSJ3m0k09C5qqrKUvsRret+iGhANbJ5R3o/l0o1enViACN0pPal7WC/BR9+sAg:EUvsRret+iGhANbJ5R3o/l0oIPo - TLSH:
T1BD40071AB2D17F9F51A82281F59D100C5065BEDF1623A4E79994CF0FEC4CF30A8785AA - Submitted as: 12ec07adae3a921b1d5b3579019bb34eb0a9b3354070d6ecfd90a72c7f7de4bf
- File type: html · Size: 173209 bytes
- Verdict: malicious (98/100)
Detections (2 of 54 engines)
- ClamAV feed: InterServer (malware): sigs.InterServer.net.HEX.Topline.js.malware.eval.string.fromcharcode.118.868.UNOFFICIAL
- Microsoft Defender: flagged
Why this verdict
The malicious score of 98/100 is the fusion of 6 weighted signals:
- ClamAV feed: InterServer (malware) flagged sigs.InterServer.net.HEX.Topline.js.malware.eval.string.fromcharcode.118.868.UNOFFICIAL (rule
sigs.InterServer.net.HEX.Topline.js.malware.eval.string.fromcharcode.118.868.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged flagged (rule
flagged) - engine signal, weight 0.55, confidence 0.85 - Obfuscated powershell script: dynamic-exec (layers: char-code+concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 2 external host(s) and 17 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://html5shim.googlecode.com/svn/trunk/html5.js, https://ywbgh.org/xmlrpc.php, https://ywbgh.org/feed/ - static signal, weight 0.35, confidence 0.60
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
283 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
Embedded URLs
- http://html5shim.googlecode.com/svn/trunk/html5.js
- https://ywbgh.org/wp-content/uploads/2016/03/ywb-logo-300x300.jpg
- https://ywbgh.org/xmlrpc.php
- https://ywbgh.org/feed/
- https://ywbgh.org/comments/feed/
- https://ywbgh.org/events/?ical=1
- https://ywbgh.org/home/feed/
- https://ywbgh.org/wp-content/plugins/wp-backgrounds-lite/includes/wp-backgrounds.css?ver=4.9.5
- https://ywbgh.org/wp-includes/css/dashicons.min.css?ver=4.9.5
- https://ywbgh.org/wp-includes/css/jquery-ui-dialog.min.css?ver=4.9.5
- https://ywbgh.org/wp-content/themes/ywbghana/framework/css/headers.css?ver=1
- https://ywbgh.org/wp-content/themes/ywbghana/framework/css/shortcodes.css?ver=1
- https://ywbgh.org/wp-content/plugins/js_composer/assets/lib/bower/flexslider/flexslider.min.css?ver=4.9
- https://ywbgh.org/wp-content/themes/ywbghana/framework/css/prettyPhoto.css?ver=1
- https://ywbgh.org/wp-content/themes/ywbghana/style.css?ver=1
- https://ywbgh.org/wp-content/themes/ywbghana/framework/css/retina.css?ver=1
- https://ywbgh.org/wp-content/themes/ywbghana/framework/css/responsive.css?ver=1
- https://ywbgh.org/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=5.0.1
- https://ywbgh.org/wp-content/plugins/flexslider/assets/css/flexslider.css?ver=1.0.1
- https://ywbgh.org/wp-content/plugins/flexslider/assets/css/style.css?ver=1.0.1
- https://ywbgh.org/wp-content/plugins/floating-social-media-icon/css/style.css?v=4.2.9&
- https://ywbgh.org/wp-content/plugins/forms-contact/style/iconfonts/css/hugeicons.css?ver=4.9.5
- https://ywbgh.org/wp-content/plugins/photo-gallery/css/bwg_frontend.css?ver=1.4.4
- https://ywbgh.org/wp-content/plugins/photo-gallery/css/font-awesome/font-awesome.css?ver=4.6.3
- https://ywbgh.org/wp-content/plugins/photo-gallery/css/jquery.mCustomScrollbar.css?ver=1.4.4
Embedded domains
- html5shim.googlecode.com
- ywbgh.org
- www.google.com
- s.w.org
- api.w.org
- www.acurax.com
- theeventscalendar.com
- maps.google.com
- www.facebook.com
- www.instagram.com
- www.youtube.com
- ywbghana.org
- fonts.googleapis.com
- ywbghana.geevapp.com
- gmail.com
- bitberglimited.com
- inoplugs.com
- www.twitter.com
- this.style.top
- schoenmann.at
- stats.startreceive.tk
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 20.184.175.1
- 4.230.171.124
- 57.154.63.210
- 52.230.59.222
- 85.210.196.11
- 20.89.1.11
- 74.178.76.54
- 135.233.95.144
- 104.18.33.89
- 13.89.179.12
- 52.110.12.33
- 52.110.12.49
- 172.215.188.232
- 172.215.188.225
- 104.46.162.224
- 20.184.175.13
- 72.145.35.102
- 52.148.114.188
- 52.110.12.31
- 52.110.12.38
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report