MALICIOUS — 225022ef7b21707d7c89a1efbe913e49f4cab26027195564c92b60e6be5e60d0
MALICIOUS — 225022ef7b21707d7c89a1efbe913e49f4cab26027195564c92b60e6be5e60d0 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the HiddenSpam family. 4 of 54 detection engines flagged it.
Identification
- SHA-256:
225022ef7b21707d7c89a1efbe913e49f4cab26027195564c92b60e6be5e60d0 - SHA-1:
d4438dbf0891ef391cf171b7ea4451f94c6c2f39 - MD5:
2cb2b86dad15f4d4392fc61a81d26b3e - ssdeep:
3072:1yGfmD9M5dOGfiSsm2XTL4/7zw48atzWzx2AIdhXk6NonCdPzY6l+qOITFtsPJrE:qoypCV - TLSH:
T1B03B338D0FC37F8156EE8613E641C2E8E52CDA332933A67185599745A12EE30DCCFA16 - Submitted as: 225022ef7b21707d7c89a1efbe913e49f4cab26027195564c92b60e6be5e60d0
- File type: html · Size: 102421 bytes
- Verdict: malicious (99/100) · Family: HiddenSpam
Detections (4 of 54 engines)
- ClamAV (daily): Js.Trojan.Obfus-633
- Microsoft Defender: Trojan:JS/HideLink.A
- Emsisoft (Emergency Kit): Generic.JS.HiddenSpam.1.D472C2F0
- Kaspersky (KVRT): Trojan-Downloader.JS.Agent.hbs
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Js.Trojan.Obfus-633 (rule
Js.Trojan.Obfus-633) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:JS/HideLink.A (rule
Trojan:JS/HideLink.A) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Generic.JS.HiddenSpam.1.D472C2F0 (rule
Generic.JS.HiddenSpam.1.D472C2F0) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan-Downloader.JS.Agent.hbs (rule
Trojan-Downloader.JS.Agent.hbs) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 5 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://gmpg.org/xfn/11, http://mma.us/wp-content/themes/f8-lite/style.css, http://mma.us/wp-content/themes/f8-lite/css/print.css - static signal, weight 0.35, confidence 0.60
- Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
279 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- fe3cr.delivery.mp.microsoft.com
- settings-win.data.microsoft.com
- v10.events.data.microsoft.com
Embedded URLs
- http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd
- http://www.w3.org/1999/xhtml
- http://gmpg.org/xfn/11
- http://mma.us/wp-content/themes/f8-lite/style.css
- http://mma.us/wp-content/themes/f8-lite/css/print.css
- http://mma.us/wp-content/themes/f8-lite/css/ie.css
- http://mma.us/feed/
- http://mma.us/xmlrpc.php
- http://mma.us/comments/feed/
- http://mma.us/wp-includes/js/jquery/jquery.js?ver=1.11.1
- http://mma.us/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1
- http://mma.us/wp-content/themes/f8-lite/js/jquery.cycle.js?ver=4.0.33
- http://mma.us/wp-content/themes/f8-lite/js/nav/superfish.js?ver=4.0.33
- http://mma.us/wp-content/themes/f8-lite/js/nav/supersubs.js?ver=4.0.33
- http://mma.us/xmlrpc.php?rsd
- http://mma.us/wp-includes/wlwmanifest.xml
- http://mma.us/sanctioned-amature-mma-resurfaces-in-nyc/
- http://mma.us/kings-of-new-york-full-rules-amature-mma/
- http://mma.us/?p=1004
- http://mma.us/underground-combat-league-10-year-anniversary-show/
- http://mma.us/wp-content/uploads/2012/03/James-Funaro-KOs-Christian-Darrow2.jpg
- http://www.cyclopedie.fr/
- http://thelbss.co.uk/
- http://7thmonarch.com/
- http://saarc-sec.org/
Embedded domains
- www.w3.org
- gmpg.org
- mma.us
- georgelou.com
- www.georgelou.com
- fightland.vice.com
- google-analytics.com
- www.cyclopedie.fr
- thelbss.co.uk
- 7thmonarch.com
- saarc-sec.org
- whiteprivilegeconference.com
- coco.co.uk
- www.africansinvermont.org
- allfootballgames.co.uk
- opentec.org
- centrefordiversity.ca
- ballerblogger.com
- www.acworth.org
- www.tinyshinyapps.co.uk
- fsx.co.za
- www.sydneyangels.net.au
Embedded IP addresses
- 2.2.3.1
- 20.184.175.9
- 4.144.132.114
- 52.123.252.226
- 4.230.171.124
- 20.165.94.54
- 20.42.179.192
- 4.150.223.103
- 74.178.240.61
- 104.46.162.224
- 20.42.73.26
- 52.110.12.4
- 52.148.114.188
- 72.154.7.109
- 52.110.12.37
More HiddenSpam samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report