SUSPICIOUS — 2b763dac587beb086c826817d81040b9e910d581082c1c1df393d4e1921d4248
SUSPICIOUS — 2b763dac587beb086c826817d81040b9e910d581082c1c1df393d4e1921d4248 is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
2b763dac587beb086c826817d81040b9e910d581082c1c1df393d4e1921d4248 - SHA-1:
9d1faa5d9edbb7071b6127e0c5b1b7cafae052f1 - MD5:
285631b967ab4343e1c3a2f3415a63d5 - ssdeep:
1536:M7yCLGm/i4i2zu5Qjdn3n0TAnDRbWwohJPiBKW0O:EGm/iSPUwDRbWwoSBKW0O - TLSH:
T1AC35B7857A9D3E9684C42512F1D812AA98C5BE2FA82030C5CB69CFCF940CD73E4756A7 - Submitted as: 2b763dac587beb086c826817d81040b9e910d581082c1c1df393d4e1921d4248
- File type: html · Size: 61909 bytes
- Verdict: suspicious (54/100)
Detections (2 of 50 engines)
- Microsoft Defender: Trojan:Script/Wacatac.B!ml
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://ogp.me/ns#, http://ogp.me/ns/fb#, https://yoast.com/wordpress/plugins/seo/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://ogp.me/ns#
- http://ogp.me/ns/fb#
- https://yoast.com/wordpress/plugins/seo/
- https://kuali.mx/
- https://schema.org
- https://kuali.mx/#website
- https://kuali.mx/#webpage
- https://kuali.mx/feed/
- https://kuali.mx/comments/feed/
- https://kuali.mx/wp-content/uploads/2018/12/favicon.png
- https://kuali.mx/wp-content/uploads/2018/12/favicon-iphone.png
- https://kuali.mx/wp-content/uploads/2018/12/favicon-ipad.png
- https://kuali.mx/wp-content/uploads/2018/12/favicon-apple_ipad.png
- https://kuali.mx/wp-content/uploads/2018/12/logo_webcolor.png
- https://kuali.mx/wp-includes/css/dist/block-library/style.min.css?ver=5.4.8
- https://kuali.mx/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=5.3.2
- https://kuali.mx/wp-content/plugins/download-monitor/assets/css/frontend.css?ver=5.4.8
- https://kuali.mx/wp-content/plugins/elements-plus/assets/css/ep-elements.css?ver=2.14.0
- https://kuali.mx/wp-content/themes/Avada/assets/css/style.min.css?ver=5.6.2
- https://kuali.mx/wp-content/themes/Avada/includes/lib/assets/fonts/fontawesome/font-awesome.min.css?ver=5.6.2
- https://kuali.mx/wp-content/themes/Avada/assets/css/ie.min.css?ver=5.6.2
- https://kuali.mx/wp-content/uploads/fusion-styles/16c70c95bf657c85fc4c585523ffc029.min.css?ver=5.4.8
- https://kuali.mx/wp-includes/js/jquery/jquery.js?ver=1.12.4-wp
- https://kuali.mx/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.4.1
- https://api.w.org/
Embedded domains
- ogp.me
- yoast.com
- kuali.mx
- schema.org
- www.google.com
- s.w.org
- api.w.org
- maxcdn.bootstrapcdn.com
- ajax.googleapis.com
- www.googletagmanager.com
- connect.facebook.net
- www.facebook.com
- www.instagram.com
- twitter.com
- www.linkedin.com
- platform.twitter.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report