SUSPICIOUS — 26bdfef1eb14e1cf9759db00a65a1844542d3d2387e89eb52d7898fb5d72744b
SUSPICIOUS — 26bdfef1eb14e1cf9759db00a65a1844542d3d2387e89eb52d7898fb5d72744b is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 1 of 53 detection engines flagged it.
Identification
- SHA-256:
26bdfef1eb14e1cf9759db00a65a1844542d3d2387e89eb52d7898fb5d72744b - SHA-1:
d4c183d083d59af64668b6710078400ce9d834bd - MD5:
f172252314ed7c3929bb3f68158f2a6d - ssdeep:
3072:BFpHNQiu5IB6OZoGSos57wFDlvdiRPvY0RdcjNtI8gp3jImKnaRJlyyMd9UBZkj9:nzvSNGDlvdiO - TLSH:
T1473FB5157A9ECA95C1C102A1F0E93064ACD67D2B34103AD5853DCBCF2DEE671E0B6CA6 - Submitted as: 26bdfef1eb14e1cf9759db00a65a1844542d3d2387e89eb52d7898fb5d72744b
- File type: html · Size: 151151 bytes
- Verdict: suspicious (54/100)
Detections (1 of 53 engines)
- Microsoft Defender: Trojan:JS/Redirector.AYLB!MTB
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (layers: char-code) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://gmpg.org/xfn/11, https://yoast.com/wordpress/plugins/seo/, https://transfers506.com/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gmpg.org/xfn/11
- https://yoast.com/wordpress/plugins/seo/
- https://transfers506.com/
- https://www.facebook.com/506transfers/
- https://secureservercdn.net/45.40.148.147/8zv.495.myftpupload.com/wp-content/uploads/2020/04/Logo-506.png
- https://schema.org
- https://transfers506.com/#organization
- https://secureservercdn.net/45.40.148.147/8zv.495.myftpupload.com/
- https://www.instagram.com/506transfers/?hl=en
- https://transfers506.com/#logo
- https://secureservercdn.net/45.40.148.147/8zv.495.myftpupload.com/wp-content/uploads/2020/04/Logo-506.png?time=1618250339
- https://transfers506.com/#website
- https://secureservercdn.net/45.40.148.147/8zv.495.myftpupload.com/#primaryimage
- https://secureservercdn.net/45.40.148.147/8zv.495.myftpupload.com/wp-content/uploads/2020/04/Logo-506.png?time=1636605481
- https://transfers506.com/#webpage
- https://transfers506.com/#primaryimage
- https://transfers506.com/#breadcrumb
- https://transfers506.com/feed/
- https://transfers506.com/comments/feed/
- https://secureservercdn.net
- https://www.exactmetrics.com/
- https://developers.google.com/analytics/devguides/collection/analyticsjs/
- https://secureservercdn.net/45.40.148.147/8zv.495.myftpupload.com/wp-content/themes/astra/assets/css/minified/style.min.css?ver=2.5.4&
- https://secureservercdn.net/45.40.148.147/8zv.495.myftpupload.com/wp-content/themes/astra/assets/fonts/astra.woff
- https://secureservercdn.net/45.40.148.147/8zv.495.myftpupload.com/wp-content/themes/astra/assets/fonts/astra.ttf
Embedded domains
- gmpg.org
- yoast.com
- transfers506.com
- www.facebook.com
- secureservercdn.net
- 8zv.495.myftpupload.com
- schema.org
- www.instagram.com
- s.w.org
- www.exactmetrics.com
- www.googletagmanager.com
- developers.google.com
- fonts.googleapis.com
- api.w.org
- code.tidio.co
- wa.me
- m.me
- player.vimeo.com
- www.w3.org
- sdk.beeketing.com
- temp.lowerbeforwarden.ml
Embedded IP addresses
- 45.40.148.147
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report