SUSPICIOUS — 1595d982491a9dcd965a188dbb2a2e187adc5c2d40abd31a7ccc56b70b8d44dd
SUSPICIOUS — 1595d982491a9dcd965a188dbb2a2e187adc5c2d40abd31a7ccc56b70b8d44dd is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 1 of 53 detection engines flagged it.
Identification
- SHA-256:
1595d982491a9dcd965a188dbb2a2e187adc5c2d40abd31a7ccc56b70b8d44dd - SHA-1:
15e074ed475038c854e84050ea2d2fd76b549a1b - MD5:
4b5864816dc1cec4a8095b91e874ccd7 - ssdeep:
192:N657zSMRnHm3whU7jnCr/CqsFhyrgydwrOxv7YXxDnxUny8G:jw1r/EhyrglO1Enunw - TLSH:
T1032762192B281EDF8BC10819E4A2997D14E9D4FF6262B8D197CCEF5C1015C71D06E68B - Submitted as: 1595d982491a9dcd965a188dbb2a2e187adc5c2d40abd31a7ccc56b70b8d44dd
- File type: html · Size: 15228 bytes
- Verdict: suspicious (58/100)
Detections (1 of 53 engines)
- Emsisoft (Emergency Kit): Trojan.HTML.Phishing.BNG
Why this verdict
The suspicious score of 58/100 is the fusion of 2 weighted signals:
- Emsisoft (Emergency Kit) flagged Trojan.HTML.Phishing.BNG (rule
Trojan.HTML.Phishing.BNG) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://login.orange.fr/?return_url=https://www.orange.fr/portail, https://r.orange.fr/r/Oid_signup?return_url=https://www.orange.fr/portail, https://mc.orange.fr?return_url=https%3A%2F%2Fwww.orange.fr%2Fportail - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://login.orange.fr/?return_url=https://www.orange.fr/portail
- https://r.orange.fr/r/Oid_signup?return_url=https://www.orange.fr/portail
- https://mc.orange.fr?return_url=https%3A%2F%2Fwww.orange.fr%2Fportail
- https://r.orange.fr/r/Oapp_Orange_EtMoi
Embedded domains
- www.orange.fr
- r.orange.fr
- login.orange.fr
- mc.orange.fr
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report