SUSPICIOUS — 36090ae208ae7e37b2cd9b2f269f080ed489aaaf0bcdee8119638938f78a74d6
SUSPICIOUS — 36090ae208ae7e37b2cd9b2f269f080ed489aaaf0bcdee8119638938f78a74d6 is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (65/100), attributed to the Group10 family. 2 of 53 detection engines flagged it.
Identification
- SHA-256:
36090ae208ae7e37b2cd9b2f269f080ed489aaaf0bcdee8119638938f78a74d6 - SHA-1:
4882073e3ceaf0325b19efa0d8a6bdc8b14c644c - MD5:
edab3124f101538893e936749ea1634c - ssdeep:
768:8pu8Ytg0Mg+MY5c3VGha0RC4+Wx/iSLida2Y:IuFg0Mg+MY5gTh4+miSLida2Y - TLSH:
T1BA2DDA2713556EA248E1094DE9240C54E038FE9F9A377CE58546EF87FC0E960CCBA89D - Submitted as: 36090ae208ae7e37b2cd9b2f269f080ed489aaaf0bcdee8119638938f78a74d6
- File type: html · Size: 29153 bytes
- Verdict: suspicious (65/100) · Family: Group10
Detections (2 of 53 engines)
- YARA: ESET research: IIS_Group10
- Microsoft Defender: Trojan:HTML/Redirector.SLYA!MTB
Why this verdict
The suspicious score of 65/100 is the fusion of 3 weighted signals:
- Obfuscated powershell script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - YARA: ESET research flagged IIS_Group10 (rule
IIS_Group10) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://www.changshun-sh.cn/wp-content/themes/dt-the7/set-cookie.php?devicePixelRatio=, http://www.changshun-sh.cn/wp-content/plugins/sitepress-multilingual-cms/res/css/language-selector.css?v=3.1.5, http://gmpg.org/xfn/11 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.changshun-sh.cn/wp-content/themes/dt-the7/set-cookie.php?devicePixelRatio=
- http://www.changshun-sh.cn/wp-content/plugins/sitepress-multilingual-cms/res/css/language-selector.css?v=3.1.5
- http://gmpg.org/xfn/11
- http://www.changshun-sh.cn/xmlrpc.php
- http://www.changshun-sh.cn/wp-content/themes/dt-the7/html5.js
- http://www.changshun-sh.cn/wp-content/themes/dt-the7/js/plugins/validator/validationEngine.jquery.css?ver=4.0.33
- http://www.changshun-sh.cn/wp-content/plugins/formcraft3/assets/css/form.css?ver=3.2.4
- http://www.changshun-sh.cn/wp-content/plugins/formcraft3/assets/css/common-elements.css?ver=3.2.4
- http://www.changshun-sh.cn/wp-content/plugins/revslider/public/assets/css/settings.css?ver=5.2.6
- http://www.changshun-sh.cn/wp-content/plugins/wp-job-manager/assets/css/frontend.css?ver=4.0.33
- http://www.changshun-sh.cn/wp-content/plugins/masterslider/public/assets/css/masterslider.main.css?ver=2.0.1
- http://www.changshun-sh.cn/wp-content/plugins/masterslider/assets/custom.css?ver=1.0
- http://www.changshun-sh.cn/wp-content/themes/dt-the7/css/main.css?ver=4.2.2
- http://www.changshun-sh.cn/wp-content/themes/dt-the7/css/font-awesome.min.css?ver=4.2.2
- http://www.changshun-sh.cn/wp-content/uploads/wp-less/dt-the7/css/custom-da06e74323.css?ver=4.2.2
- http://www.changshun-sh.cn/wp-content/themes/dt-the7/css/media.css?ver=4.2.2
- http://www.changshun-sh.cn/wp-content/themes/dt-the7/royalslider/royalslider.css?ver=4.2.2
- http://www.changshun-sh.cn/wp-content/themes/dt-the7/style.css?ver=4.2.2
- http://www.changshun-sh.cn/wp-includes/js/jquery/jquery.js?ver=1.11.1
- http://www.changshun-sh.cn/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1
- http://www.changshun-sh.cn/wp-content/plugins/revslider/public/assets/js/jquery.themepunch.tools.min.js?ver=5.2.6
- http://www.changshun-sh.cn/wp-content/plugins/revslider/public/assets/js/jquery.themepunch.revolution.min.js?ver=5.2.6
- http://www.changshun-sh.cn/wp-content/themes/dt-the7/js/modernizr.js?ver=4.2.2
- http://www.changshun-sh.cn/wp-content/themes/dt-the7/js/svg-icons.js?ver=4.2.2
- http://www.changshun-sh.cn/
Embedded domains
- www.changshun-sh.cn
- gmpg.org
- dev.3dunion.cn
- beian.miit.gov.cn
- chrome.360.cn
- www.firefox.com.cn
- ie.sogou.com
- www.maxthon.cn
- liulanqi.baidu.com
- www.theworld.cn
- windows.microsoft.com
- www.google.com
- support.apple.com
- www.opera.com
- wp-rocket.me
Embedded IP addresses
- 4.1.3.1
More Group10 samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report