SUSPICIOUS — 2de99b563224ba7482bae750f72534199a666cdbf3d5967cc7dbe3ec5a886cca
SUSPICIOUS — 2de99b563224ba7482bae750f72534199a666cdbf3d5967cc7dbe3ec5a886cca is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 1 of 53 detection engines flagged it.
Identification
- SHA-256:
2de99b563224ba7482bae750f72534199a666cdbf3d5967cc7dbe3ec5a886cca - SHA-1:
8aee6e86ba05788f376a9a4db2d2b6e5f2ba3c0b - MD5:
acee6cdb545312ce396b8e94e2dea662 - ssdeep:
1536:5IRIOITIwIgIiKZgNDfIwIGI5IVJ7SqIRIOITIwIgIiKZgNDfIwIGI5IVJ7SZfa3:8faETfETB1ioM92pAw4HjKiEyKW0zL - TLSH:
T1AB3F0883719E6C86C6DB169B13C59D103CC1A65E0478DDC6B0FF5BE0B19EAA070885EB - Submitted as: 2de99b563224ba7482bae750f72534199a666cdbf3d5967cc7dbe3ec5a886cca
- File type: html · Size: 149566 bytes
- Verdict: suspicious (54/100)
Detections (1 of 53 engines)
- Microsoft Defender: Trojan:Script/Wacatac.C!ml
Why this verdict
The suspicious score of 54/100 is the fusion of 4 weighted signals:
- Obfuscated javascript script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 20 external host(s) at runtime (21 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://ogp.me/ns/fb#, http://es-pic2.ciao.com/es/10771555.jpg, https://www.kelisto.es/system/images/W1siZiIsIjIwMTcvMDkvMTEvMTYvNTMvNDMvZjQzZWUwMjMtMjViZi00YmRkLTg4Y2YtMzVjYjEwYTg5ZWFlL3ByZXN0YW1vc19yZWZvcm1hX2hvZ2FyLmpwZyJdLFsicCIsInRodW1iIiwiOTAweDUwMCMiXV0/prestamos_reforma_hogar.jpg - static signal, weight 0.35, confidence 0.60
- Extracted generic config (10 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
279 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- settings-win.data.microsoft.com
- www.msn.com
Embedded URLs
- http://ogp.me/ns/fb#
- https://minicreditos.info/wp-content/uploads/2016/01/Creditovictoria-1024x393.jpg
- https://dineroybancos.es/wp-content/uploads/2016/02/DineroyBancos.png
- https://www.alertaprestamo.es/wp-content/uploads/2017/06/Freezl-Prestamos5.jpg
- http://si.pae.cc/convenios/wp-content/uploads/2015/12/Promo-PlaniYa.png
- http://www.multimedios.com/files/home_article2x1/uploads/2017/09/18/59bfeced00d97.jpeg
- http://es-pic2.ciao.com/es/10771555.jpg
- https://www.kelisto.es/system/images/W1siZiIsIjIwMTcvMDkvMTEvMTYvNTMvNDMvZjQzZWUwMjMtMjViZi00YmRkLTg4Y2YtMzVjYjEwYTg5ZWFlL3ByZXN0YW1vc19yZWZvcm1hX2hvZ2FyLmpwZyJdLFsicCIsInRodW1iIiwiOTAweDUwMCMiXV0/prestamos_reforma_hogar.jpg
- https://www.creditodb.es/wp-content/uploads/2016/03/Prestamo-Naranja-ING-Direct-Asnef.png
- https://i.ytimg.com/vi/McPQFPCYZ9Q/hqdefault.jpg
- http://media.diariolasamericas.com/adjuntos/216/imagenes/001/090/0001090941.jpg
- http://creditokandio529.weebly.com/
- https://ajax.googleapis.com/ajax/libs/jquery/1.8.3/jquery.min.js
- https://www.google.com/recaptcha/api.js
- http://creditokandio529.weebly.com/1/post/2017/11/requisitos-prestamo-evo.html
- http://twitter.com/share?url=http://creditokandio529.weebly.com/1/post/2017/11/requisitos-prestamo-evo.html
- http://creditokandio529.weebly.com/1/post/2017/11/prestamos-personales-chihuahua.html
- http://twitter.com/share?url=http://creditokandio529.weebly.com/1/post/2017/11/prestamos-personales-chihuahua.html
- http://creditokandio529.weebly.com/1/post/2017/11/prestamo-ing-nomina.html
- http://twitter.com/share?url=http://creditokandio529.weebly.com/1/post/2017/11/prestamo-ing-nomina.html
- https://definanzas.com/wp-content/uploads/2017/01/solicitar-ayudas-alquiler-madrid-2016-direcciones-600x276.jpg
- http://www.bolsamania.com/declaracion-impuestos-renta/wp-content/uploads/2016/02/comprar-casa-a-los-hijos.jpg
- http://creditokandio529.weebly.com/1/post/2017/11/pagar-impuesto-ayuda-a-obtener-una-vivienda.html
- http://twitter.com/share?url=http://creditokandio529.weebly.com/1/post/2017/11/pagar-impuesto-ayuda-a-obtener-una-vivienda.html
- http://expertoencreditos.com.mx/wp-content/uploads/2013/02/Pr%C3%A9stamos-por-Internet-602x300.jpg
Embedded domains
- ogp.me
- minicreditos.info
- dineroybancos.es
- www.alertaprestamo.es
- si.pae.cc
- www.multimedios.com
- es-pic2.ciao.com
- www.kelisto.es
- www.creditodb.es
- i.ytimg.com
- media.diariolasamericas.com
- creditokandio529.weebly.com
- cdn2.editmysite.com
- fonts.googleapis.com
- cdn1.editmysite.com
- ajax.googleapis.com
- www.weebly.com
- www.google.com
- p.us
- f.in
- twitter.com
- definanzas.com
- www.bolsamania.com
- expertoencreditos.com.mx
- creditos.mejortrato.com.mx
Embedded IP addresses
- 4.207.44.69
- 52.123.252.219
- 172.215.188.225
- 57.155.101.212
- 4.230.171.124
- 4.144.132.223
- 135.233.95.144
- 20.184.175.22
- 74.178.76.54
- 74.179.77.204
- 20.236.44.162
- 52.123.128.14
- 172.66.2.5
- 172.178.240.163
- 135.233.95.80
- 203.26.79.13
- 52.148.114.188
- 72.154.7.97
- 52.110.12.46
- 52.110.12.8
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report