MALICIOUS — 1e05dfc72bbd95f7c7b8b4b9b4d68f3db8a2727e981d6d0fdc54d322f8b9f88e
MALICIOUS — 1e05dfc72bbd95f7c7b8b4b9b4d68f3db8a2727e981d6d0fdc54d322f8b9f88e is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100), attributed to the HTML family. 3 of 51 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1e05dfc72bbd95f7c7b8b4b9b4d68f3db8a2727e981d6d0fdc54d322f8b9f88e - SHA-1:
9c3164a030e2067636bf51b48cb4a15fa34c7e1e - MD5:
52ab362a5c5a2036d6df86def71ebdf0 - ssdeep:
1536:eIRIOITIwIgI1KZgNDxIwIGI5IKJ7S6IRIOITIwIgI2KZgND2IwIGI5ImJ7S81jC:01jOnkkL - TLSH:
T1EA336241AA8B8CCF818B164D52510B84B49DD98E40A2DBDFF0E4CD2ADD6FB50D26C4DB - Submitted as: 1e05dfc72bbd95f7c7b8b4b9b4d68f3db8a2727e981d6d0fdc54d322f8b9f88e
- File type: html · Size: 49980 bytes
- Verdict: malicious (95/100) · Family: HTML
Detections (3 of 51 engines)
- Microsoft Defender: Trojan:HTML/Phish.B!atmn
- Emsisoft (Emergency Kit): GT:JS.ObfscRed.2.0C527B95
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 95/100 is the fusion of 9 weighted signals:
- Memory forensics: 4 finding(s), e.g. RWX/private injected region in taskhostw.exe (pid 7368) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:HTML/Phish.B!atmn (rule
Trojan:HTML/Phish.B!atmn) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged GT:JS.ObfscRed.2.0C527B95 (rule
GT:JS.ObfscRed.2.0C527B95) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec (layers: char-code+concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://ogp.me/ns/fb#, http://oasispin.weebly.com/uploads/1/2/6/9/126905046/821987156_orig.jpg, http://oasispin.weebly.com/2/post/2020/09/skate-2-ps3-rom.html - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (6 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Extracted generic config (6 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
274 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- www.bing.com
- desktop-hsgcbep
- config.edge.skype.com
- tas02.sls.update.microsoft.com
- ctldl.windowsupdate.com
- settings-win.data.microsoft.com
- to-do.microsoft.com
- dns.msftncsi.com
- staging.to-do.microsoft.com
- edge.microsoft.com
- teams.microsoft.com
- ecs.office.com
- watson.events.data.microsoft.com
- aps.prod.windows.com
Embedded URLs
- http://ogp.me/ns/fb#
- http://oasispin.weebly.com/uploads/1/2/6/9/126905046/821987156_orig.jpg
- http://oasispin.weebly.com/2/post/2020/09/skate-2-ps3-rom.html
- https://ajax.googleapis.com/ajax/libs/jquery/1.8.3/jquery.min.js
- https://www.google.com/recaptcha/api.js
- https://oasispin.weebly.com/2/post/2020/09/skate-2-ps3-rom.html
- http://twitter.com/share?url=https://oasispin.weebly.com/2/post/2020/09/skate-2-ps3-rom.html
- http://oasispin.weebly.com/blog/skate-2-ps3-rom&is_mobile=&r=3&is_light=0
- https://www.weebly.com/signup?utm_source=internal&utm_medium=footer
Embedded domains
- ogp.me
- oasispin.weebly.com
- fonts.googleapis.com
- cdn2.editmysite.com
- cdn1.editmysite.com
- ajax.googleapis.com
- www.weebly.com
- www.google.com
- twitter.com
- google-analytics.com
- test.name
- ec.editmysite.com
- connect.facebook.net
- tter.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.cloud.microsoft
More HTML samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report