SUSPICIOUS — 15c87763f3f5467450bf843b9804542d70953a475585bc06e984f462e76ff276
SUSPICIOUS — 15c87763f3f5467450bf843b9804542d70953a475585bc06e984f462e76ff276 is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
15c87763f3f5467450bf843b9804542d70953a475585bc06e984f462e76ff276 - SHA-1:
61bf1d1afdd10a22790cad854911448266e1cbb6 - MD5:
01b593b2f8ffc1531eca95f2eeb54223 - ssdeep:
48:LMJNplR8NRC38SIt3ycqvgr9ruykH7voEzS3ST:LA7H8a70prMnb1zS3ST - TLSH:
T1D914309F92611F7AC1A801A2016CC8E15683F62F5B446976DFFDCD96988C1E2E090537 - Submitted as: 15c87763f3f5467450bf843b9804542d70953a475585bc06e984f462e76ff276
- File type: html · Size: 1648 bytes
- Verdict: suspicious (54/100)
Detections (3 of 50 engines)
- Microsoft Defender: Trojan:Script/Wacatac.B!ml
- Emsisoft (Emergency Kit): Trojan.Agent.FRPD
- Kaspersky (KVRT): HEUR:Trojan.HTML.Phish.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 54/100 is the fusion of 4 weighted signals:
- Contacted 24 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://mail.ppscn.com/public/image/projectIcon.ico, http://images.all-free-download.com/images/graphicthumb/mailbox_clip_art_12155.jpg - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (2 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
273 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- searchapp.bundleassets.example
- inference.location.live.net
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- settings-win.data.microsoft.com
- officeclient.microsoft.com
- www.bing.com
- tas02.sls.update.microsoft.com
- v10.events.data.microsoft.com
- to-do.microsoft.com
Embedded URLs
- http://mail.ppscn.com/public/image/projectIcon.ico
- http://images.all-free-download.com/images/graphicthumb/mailbox_clip_art_12155.jpg
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- mail.ppscn.com
- images.all-free-download.com
- megababe.co.uk
Embedded IP addresses
- 52.123.128.14
- 51.104.15.252
- 85.210.196.11
- 52.110.12.20
- 74.179.77.204
- 4.150.223.96
- 20.231.239.246
- 135.234.160.244
- 52.110.12.38
- 57.155.104.224
- 52.230.60.54
- 20.236.44.162
- 20.42.65.94
- 135.233.45.222
- 4.230.171.124
- 40.84.85.40
- 74.178.240.51
- 40.79.141.153
- 72.145.35.109
- 52.168.112.66
- 52.123.129.14
- 52.148.114.188
- 52.110.12.25
- 135.233.95.80
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report