SUSPICIOUS — 377b7bd485d82f8b04ff9f10c7a1adbcdde0e93d6131c3a4699ec185700abb05
SUSPICIOUS — 377b7bd485d82f8b04ff9f10c7a1adbcdde0e93d6131c3a4699ec185700abb05 is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
377b7bd485d82f8b04ff9f10c7a1adbcdde0e93d6131c3a4699ec185700abb05 - SHA-1:
3b2ced47459266f760020b2697be582614b0c4ad - MD5:
b87c9f2dc1fc8045c40f6298a2314d80 - ssdeep:
768:t6oa+gpaEWlyHdfqlIrq5J7YwYsAtcG+yKuEKM+RCFQ2gO:t6oaZsyHY5FYwYXtcryKuEKMkCFD - TLSH:
T13633B81A360D7A4F14D0C22356644BE4F0CFA4ABA633C0F6D692BF94DD2CD606C69963 - Submitted as: 377b7bd485d82f8b04ff9f10c7a1adbcdde0e93d6131c3a4699ec185700abb05
- File type: html · Size: 48221 bytes
- Verdict: suspicious (54/100)
Detections (2 of 50 engines)
- Microsoft Defender: TrojanClicker:JS/Faceliker.N
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated powershell script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css, http://cvfanatic.blogspot.com/favicon.ico, http://cvfanatic.blogspot.com/feeds/posts/default - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.google.com/2005/gml/b
- http://www.google.com/2005/gml/data
- http://www.google.com/2005/gml/expr
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css
- http://cvfanatic.blogspot.com/favicon.ico
- http://cvfanatic.blogspot.com/2011/10/mission-frightening-friends.html
- http://cvfanatic.blogspot.com/feeds/posts/default
- http://cvfanatic.blogspot.com/feeds/posts/default?alt=rss
- https://www.blogger.com/feeds/4467544956822473438/posts/default
- http://cvfanatic.blogspot.com/feeds/2388524526444772132/comments/default
- http://assets.cityville.zynga.com/hashed/a3e6892cb7812321172c48e10b6591ed.png
- https://lh3.googleusercontent.com/proxy/2U2e4rsyNE2ia9_vbA7Ig7yTq7zqS0dKl74rlzdiO_VwCks-JgNatZ6x0nnlusD1rwrG_vn7jTjO1hgh8CfakkZ_5ZIdtBhr-tBCQRdabyT6_VfnK-2AEpW0IYmuCb2H0g=w1200-h630-p-k-no-nu
- http://www.bleuken.com/
- http://i178.photobucket.com/albums/w243/bleuken/bottom.gif
- http://i178.photobucket.com/albums/w243/bleuken/link_split.jpg
- http://i178.photobucket.com/albums/w243/bleuken/link_hover.jpg
- http://i178.photobucket.com/albums/w243/bleuken/arrow.gif
- https://www.blogger.com/dyn-css/authorization.css?targetBlogID=4467544956822473438&
- https://apis.google.com/js/plusone.js
- http://gi86.photobucket.com/groups/k115/F9377IFNNT/top.gif
- http://3.bp.blogspot.com/-1mR1ReCjMdg/Ta3zN8k4reI/AAAAAAAAAMk/Slm3KXtF_q4/s1600/87.png
- http://cvfanatic.blogspot.com/
- http://cvfanatic.blogspot.com/search/label/CityVille%20Missions
- http://cvfanatic.blogspot.com/2011/10/mission-frightening-friends.html#comment-form
Embedded domains
- www.w3.org
- www.google.com
- www.blogger.com
- cvfanatic.blogspot.com
- assets.cityville.zynga.com
- lh3.googleusercontent.com
- www.bleuken.com
- i178.photobucket.com
- blogspot.com
- apis.google.com
- pagead2.googlesyndication.com
- gi86.photobucket.com
- 3.bp.blogspot.com
- static.ak.fbcdn.net
- i.imgur.com
- www.facebook.com
- like.style.top
- yourjavascript.com
- claremontdesign.com
- www.blogblog.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report