MALICIOUS — 15ce5b744b20e5ac50fd1fe2c4eb6a3b473a1f43d0049acf243494a627ac67a6
MALICIOUS — 15ce5b744b20e5ac50fd1fe2c4eb6a3b473a1f43d0049acf243494a627ac67a6 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the HideLink family. 4 of 51 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
15ce5b744b20e5ac50fd1fe2c4eb6a3b473a1f43d0049acf243494a627ac67a6 - SHA-1:
6cdf83521b22bece1e22ed94d65a16222f8948ac - MD5:
20d0c3916471475db9a79868d92c6032 - ssdeep:
384:Ojd6RdOTKTqi7QqBnqLg/85k+bz/cGgDD/qxDlFNqC7LZoPTr:tRdOGOilBqc/85V/cG4D/qxzNH5i - TLSH:
T1392BD81963513BDF44E60816D10C54A8C4E2F5DFE132A0E99BD8EBC9A474E71C86FA83 - Submitted as: 15ce5b744b20e5ac50fd1fe2c4eb6a3b473a1f43d0049acf243494a627ac67a6
- File type: html · Size: 22917 bytes
- Verdict: malicious (98/100) · Family: HideLink
Detections (4 of 51 engines)
- ClamAV (daily): Js.Trojan.Obfus-633
- Microsoft Defender: Trojan:JS/HideLink.A
- Emsisoft (Emergency Kit): Trojan.HideLink.1
- Kaspersky (KVRT): Trojan-Downloader.JS.Agent.hbs
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Js.Trojan.Obfus-633 (rule
Js.Trojan.Obfus-633) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:JS/HideLink.A (rule
Trojan:JS/HideLink.A) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.HideLink.1 (rule
Trojan.HideLink.1) - engine signal, weight 0.55, confidence 0.85 - Obfuscated powershell script: dynamic-exec (layers: char-code) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://gmpg.org/xfn/11, http://theboondockbetties.com/wp-content/themes/mystique/style.css, http://theboondockbetties.com/xmlrpc.php - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 1 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
277 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- svc.ms-acdc-teams.office.com
- mr-b02.tm-azurefd.net
- searchapp.bundleassets.example
- settings-prod-eus2-2-tagged.eastus2.cloudapp.azure.com
- staging.to-do.officeppe.com
- s-0005.dual-s-msedge.net
- teams.cloud.microsoft
- outlook.office.com
- SYD-efz.ms-acdc.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- www.msftconnecttest.com
- ln-0007.ln-msedge.net
- onedsblobvmssprdeus03.eastus.cloudapp.azure.com
- teams-mrc-ww-perf.tm-4.office.com
- mr-b01.tm-azurefd.net
- onedscolprdfrc01.francecentral.cloudapp.azure.com
- onedscolprdcus57.centralus.cloudapp.azure.com
- onedscolprdcus71.centralus.cloudapp.azure.com
- onedscolprdwus51.westus.cloudapp.azure.com
Embedded URLs
- http://gmpg.org/xfn/11
- http://theboondockbetties.com/wp-content/themes/mystique/style.css
- http://theboondockbetties.com/xmlrpc.php
- http://theboondockbetties.com/feed/
- http://theboondockbetties.com/comments/feed/
- http://theboondockbetties.com/2010/02/19/spaghetti-bolognese/feed/
- http://theboondockbetties.com/wp-content/plugins/nextgen-gallery/css/nggallery.css?ver=1.0.0
- http://theboondockbetties.com/wp-content/plugins/nextgen-gallery/shutter/shutter-reloaded.css?ver=1.3.4
- http://theboondockbetties.com/wp-content/plugins/nextgen-gallery/shutter/shutter-reloaded.js?ver=1.3.3
- http://theboondockbetties.com/wp-includes/js/jquery/jquery.js?ver=1.11.3
- http://theboondockbetties.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1
- http://theboondockbetties.com/wp-content/plugins/nextgen-gallery/js/jquery.cycle.all.min.js?ver=2.9995
- http://theboondockbetties.com/wp-content/plugins/nextgen-gallery/js/ngg.slideshow.min.js?ver=1.05
- http://theboondockbetties.com/xmlrpc.php?rsd
- http://theboondockbetties.com/wp-includes/wlwmanifest.xml
- http://theboondockbetties.com/2010/02/07/juliebenz-s-chocolate-pistachio-cake-recipe/
- http://theboondockbetties.com/2010/02/23/oven-roasted-sausage-and-peppers/
- http://theboondockbetties.com/2010/02/19/spaghetti-bolognese/
- http://theboondockbetties.com/?p=22
- http://theboondockbetties.com/wp-content/plugins/social-media-widget/social_widget.css
- http://www.givingsight.org/
- http://www.arizonalawreview.org/
- http://nofaxcash4kf.com/
- http://gangoffour.co.uk/
- http://nofaxcash4ks.com/payday-loan/short-term-payday-loan
Embedded domains
- gmpg.org
- theboondockbetties.com
- s.w.org
- www.givingsight.org
- www.arizonalawreview.org
- nofaxcash4kf.com
- gangoffour.co.uk
- nofaxcash4ks.com
- architectstudio3d.com
- cashadvance4kf.com
- songart.co.uk
- www.akca.org
- 1hourpayday4kf.com
- www.annabolteus.com
- parkinsonsconference.com.au
- www.theinformationlab.co.uk
- avoidaclaim.com
- chalkfarmdesign.com.au
- www.facebook.com
- www.twitter.com
- www.youtube.com
- theboondockbetties.tumblr.com
- feeds.feedburner.com
- cranialspasm.com
- feedproxy.google.com
Embedded IP addresses
- 23.33.238.100
More HideLink samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report