SUSPICIOUS — 37730270b66d2d4fc9c73d534e4a4cb7ae594d27222d27d0b33cd191d1819b2b
SUSPICIOUS — 37730270b66d2d4fc9c73d534e4a4cb7ae594d27222d27d0b33cd191d1819b2b is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 0 of 50 detection engines flagged it.
Identification
- SHA-256:
37730270b66d2d4fc9c73d534e4a4cb7ae594d27222d27d0b33cd191d1819b2b - SHA-1:
bc1c5e2314b67df6c531920a46f27e0d20466166 - MD5:
caaa539e38f06d9da1618b8600dcddd0 - ssdeep:
768:CT0BuIxTNGOtdDs379IaI2I2bICI5IXIcIaImI2e1TGPi:CoBuaxGO/cJ1Pi - TLSH:
T1D2305D8BA1563A7FF89514217BDC8150E8FBD9EFE00A28DCDCC6C9ACD408E547A2C419 - Submitted as: 37730270b66d2d4fc9c73d534e4a4cb7ae594d27222d27d0b33cd191d1819b2b
- File type: html · Size: 37531 bytes
- Verdict: suspicious (54/100)
Detections (0 of 50 engines)
No engine flagged this sample.
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (layers: base64) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://www.maxaimnetworks.com/px.js?ch=1, http://www.maxaimnetworks.com/px.js?ch=2, http://www.maxaimnetworks.com/sk-logabpstatus.php?a=cGhwSldhdkZScmt6Zlc5Z2NqaW5FNEIvRGJSSHE1RHRublUxcjZ2VXVzNlBPbGJrMG9seHdhZUZyUCtxb1dJNlcybWZ1VnJ0YVoyZ1l0d3dJbkl4RzVOQTRZQkdMcXpucFRxVWNWQ3lRNkRTK1lzekVIYXBCWXVJRVJNdFlqYWs=&b= - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.w3.org/TR/html4/strict.dtd
- http://www.maxaimnetworks.com/px.js?ch=1
- http://www.maxaimnetworks.com/px.js?ch=2
- http://www.maxaimnetworks.com/sk-logabpstatus.php?a=cGhwSldhdkZScmt6Zlc5Z2NqaW5FNEIvRGJSSHE1RHRublUxcjZ2VXVzNlBPbGJrMG9seHdhZUZyUCtxb1dJNlcybWZ1VnJ0YVoyZ1l0d3dJbkl4RzVOQTRZQkdMcXpucFRxVWNWQ3lRNkRTK1lzekVIYXBCWXVJRVJNdFlqYWs=&b=
- http://i1.cdn-image.com/__media__/fonts/ubuntu-r/ubuntu-r.eot
- http://i1.cdn-image.com/__media__/fonts/ubuntu-r/ubuntu-r.eot?#iefix
- http://i1.cdn-image.com/__media__/fonts/ubuntu-r/ubuntu-r.woff
- http://i1.cdn-image.com/__media__/fonts/ubuntu-r/ubuntu-r.woff2
- http://i1.cdn-image.com/__media__/fonts/ubuntu-r/ubuntu-r.ttf
- http://i1.cdn-image.com/__media__/fonts/ubuntu-r/ubuntu-r.otf
- http://i1.cdn-image.com/__media__/fonts/ubuntu-r/ubuntu-r.svg#ubuntu-r
- http://i1.cdn-image.com/__media__/fonts/ubuntu-b/ubuntu-b.eot
- http://i1.cdn-image.com/__media__/fonts/ubuntu-b/ubuntu-b.eot?#iefix
- http://i1.cdn-image.com/__media__/fonts/ubuntu-b/ubuntu-b.woff
- http://i1.cdn-image.com/__media__/fonts/ubuntu-b/ubuntu-b.woff2
- http://i1.cdn-image.com/__media__/fonts/ubuntu-b/ubuntu-b.ttf
- http://i1.cdn-image.com/__media__/fonts/ubuntu-b/ubuntu-b.otf
- http://i1.cdn-image.com/__media__/fonts/ubuntu-b/ubuntu-b.svg#ubuntu-b
- http://i1.cdn-image.com/__media__/pics/12471/bodybg.png
- http://i1.cdn-image.com/__media__/pics/12471/kwbg.jpg
- http://i1.cdn-image.com/__media__/pics/12471/libg.png
- http://i1.cdn-image.com/__media__/pics/12471/arrow.png
- http://i1.cdn-image.com/__media__/pics/12471/libgh.png
- http://i1.cdn-image.com/__media__/pics/12471/logo.png
- http://i1.cdn-image.com/__media__/pics/12471/search-icon.png
Embedded domains
- www.w3.org
- www.maxaimnetworks.com
- maxaimnetworks.com
- i1.cdn-image.com
- www.networksolutions.com
- pxlgnpgecom-a.akamaihd.net
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report