MALICIOUS — 2c3bfdc1bd74cb690775958583469ba422b9ed7d541ddfec75cc42a44f7d7cbf
MALICIOUS — 2c3bfdc1bd74cb690775958583469ba422b9ed7d541ddfec75cc42a44f7d7cbf is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 1 of 54 detection engines flagged it.
Identification
- SHA-256:
2c3bfdc1bd74cb690775958583469ba422b9ed7d541ddfec75cc42a44f7d7cbf - SHA-1:
d1bcdc569df73a87e3e184e0368fc8c833aab4c5 - MD5:
c1c4839146e5dc9b9b8b96027966c049 - ssdeep:
768:weSil0kDxb3w24XFJWFTfN9z9iINU6XuKoG9QS8mlEKM0jQpfl2nd:w09FTfNx99Jbom1EpfM - TLSH:
T15E33F94AB3053E4F14E08117557C0BD581CADB9BA63351F4E9B3AF48EC39EA0AC08D56 - Submitted as: 2c3bfdc1bd74cb690775958583469ba422b9ed7d541ddfec75cc42a44f7d7cbf
- File type: html · Size: 48145 bytes
- Verdict: malicious (96/100)
Detections (1 of 54 engines)
- ClamAV (daily): Win.Trojan.Crypt-291
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Crypt-291 (rule
Win.Trojan.Crypt-291) - engine signal, weight 0.90, confidence 0.95 - Obfuscated powershell script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 2 external host(s) and 17 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css, http://beauty-licioux.blogspot.com/favicon.ico, http://beauty-licioux.blogspot.com/feeds/posts/default - static signal, weight 0.35, confidence 0.60
- Extracted generic config (16 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
279 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- licensing.mp.microsoft.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- www.bing.com
- assets.msn.com
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.google.com/2005/gml/b
- http://www.google.com/2005/gml/data
- http://www.google.com/2005/gml/expr
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css
- http://beauty-licioux.blogspot.com/favicon.ico
- http://beauty-licioux.blogspot.com/2009/02/item-17snore-stopper-rm10.html
- http://beauty-licioux.blogspot.com/feeds/posts/default
- http://beauty-licioux.blogspot.com/feeds/posts/default?alt=rss
- https://www.blogger.com/feeds/2676696745191380843/posts/default
- http://beauty-licioux.blogspot.com/feeds/1100381819840835020/comments/default
- http://1.bp.blogspot.com/_MCnVxSooc2w/SYgkqidAT9I/AAAAAAAABOc/iD2jz3zVpzs/s400/snore.jpg
- http://1.bp.blogspot.com/_MCnVxSooc2w/SYgkqidAT9I/AAAAAAAABOc/iD2jz3zVpzs/w1200-h630-p-k-no-nu/snore.jpg
- http://ipietoon.blogspot.com
- http://www.bloggerstyles.com
- http://1.bp.blogspot.com/_6pbSFKC8YH4/SaK5bcBnWlI/AAAAAAAAAR8/JuAipwinPNE/s1600/topnavbar.png
- http://2.bp.blogspot.com/_6pbSFKC8YH4/SaVsMwsT3iI/AAAAAAAAATU/jrHCkTYCb_c/s1600/headerfashion.png
- http://2.bp.blogspot.com/_6pbSFKC8YH4/SaVsoPWSXcI/AAAAAAAAATc/8qL09Kv7Isk/s1600/navbarmenu.png
- http://2.bp.blogspot.com/_6pbSFKC8YH4/SaK5bdRU4EI/AAAAAAAAAR0/fbFBy1BeBjY/s1600/search.png
- http://2.bp.blogspot.com/_6pbSFKC8YH4/SaLNjaPcrQI/AAAAAAAAATE/E81xH-Uaugo/s1600/toppost.png
- http://2.bp.blogspot.com/_6pbSFKC8YH4/SaK8xDVlmuI/AAAAAAAAASE/KeNFZ8eN5vg/s1600/blockquote.png
- http://2.bp.blogspot.com/_nxOMLf2KJwU/SaOIKuUicgI/AAAAAAAABFk/YION5r430kE/s1600/botpost.png
- http://3.bp.blogspot.com/_6pbSFKC8YH4/SaVrwBU_UbI/AAAAAAAAATM/61vZff0Dvq0/s1600/footerbottom.png
- https://www.blogger.com/dyn-css/authorization.css?targetBlogID=2676696745191380843&
- https://www.blogger.com/go/adspersonalization
Embedded domains
- www.w3.org
- www.google.com
- www.blogger.com
- beauty-licioux.blogspot.com
- 1.bp.blogspot.com
- ipietoon.blogspot.com
- www.bloggerstyles.com
- 2.bp.blogspot.com
- 3.bp.blogspot.com
- blogspot.com
- apis.google.com
- pagead2.googlesyndication.com
- hotmail.com
- feedburner.google.com
- www5.shoutmix.com
- www.shoutmix.com
- impeccable-dolcevita.blogspot.com
- farm4.static.flickr.com
- www.blogblog.com
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 20.52.64.201
- 52.123.252.194
- 52.230.60.54
- 4.230.171.124
- 52.110.12.33
- 52.110.12.51
- 85.210.196.11
- 20.42.179.192
- 4.150.223.102
- 4.150.223.104
- 52.110.12.56
- 52.110.12.54
- 72.154.7.108
- 52.148.114.188
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report