MALICIOUS — 377e811cfd6af7dd31d05eb7c9782de061987631b0617e074cc3f4547be588ce
MALICIOUS — 377e811cfd6af7dd31d05eb7c9782de061987631b0617e074cc3f4547be588ce is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
377e811cfd6af7dd31d05eb7c9782de061987631b0617e074cc3f4547be588ce - SHA-1:
878009b7e60112c772ce94a9316779b6da52222d - MD5:
25b68d62fe2fb4b7cbd17ae2df6df10c - ssdeep:
1536:aLj239DNUNq2mFRzRIrGg4RHQ/tORgy+fM6mOiQUaE507:a/eRUNqLFRzRIig4RHQ/tO2y+fM6mOiG - TLSH:
T12138201492027FFF14800306FEA99914F01862CEA77A5CF28685DE59FD1EE209DE9D8D - Submitted as: 377e811cfd6af7dd31d05eb7c9782de061987631b0617e074cc3f4547be588ce
- File type: html · Size: 83296 bytes
- Verdict: malicious (93/100)
Detections (3 of 50 engines)
- ClamAV (daily): Js.Coinminer.Generic-6836639-1
- Microsoft Defender: Trojan:JS/CoinHive.B
- Kaspersky (KVRT): HEUR:Trojan.JS.Miner.gen
Why this verdict
The malicious score of 93/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Js.Coinminer.Generic-6836639-1 (rule
Js.Coinminer.Generic-6836639-1) - engine signal, weight 0.90, confidence 0.95 - Obfuscated javascript script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://www.selfpackshipping.com/xmlrpc.php, http://www.selfpackshipping.com/wp-content/themes/sevenfold, http://selfpackshipping.com/images/favicon-1.ico - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.selfpackshipping.com/xmlrpc.php
- http://www.selfpackshipping.com/wp-content/themes/sevenfold
- http://selfpackshipping.com/images/favicon-1.ico
- https://yoast.com/wordpress/plugins/seo/
- https://www.selfpackshipping.com/brisbane/
- http://www.cargomaster.com.au/wp-content/uploads/2012/08/img_slider_05-564x350.jpg
- https://schema.org
- https://www.selfpackshipping.com/#website
- https://www.selfpackshipping.com/
- https://www.selfpackshipping.com/brisbane/#primaryimage
- https://www.selfpackshipping.com/brisbane/#webpage
- https://www.selfpackshipping.com/brisbane/#breadcrumb
- https://www.selfpackshipping.com/feed/
- https://www.selfpackshipping.com/comments/feed/
- http://www.selfpackshipping.com/wp-includes/css/dist/block-library/style.min.css?ver=5.8.2
- http://www.selfpackshipping.com/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=5.4
- http://www.selfpackshipping.com/wp-content/plugins/revslider/public/assets/css/settings.css?ver=5.4.3
- http://fonts.googleapis.com/css?family=Roboto%3A100%2C400%2C400italic%2C300%2C300italic%2C700%2C700italic%2C900&
- http://www.selfpackshipping.com/wp-content/themes/sevenfold/css/bootstrap.css?ver=5.8.2
- http://www.selfpackshipping.com/wp-content/themes/sevenfold/css/swipebox.css?ver=5.8.2
- http://www.selfpackshipping.com/wp-content/themes/sevenfold/css/screen.css?ver=5.8.2
- http://seafreightshipping.com/staging/wp-content/uploads/2014/07/check-256.png
- http://www.selfpackshipping.com/wp-content/themes/sevenfold-child/style.css?ver=5.8.2
- http://www.selfpackshipping.com/wp-includes/js/jquery/jquery.min.js?ver=3.6.0
- http://www.selfpackshipping.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.3.2
Embedded domains
- www.selfpackshipping.com
- selfpackshipping.com
- yoast.com
- www.cargomaster.com.au
- schema.org
- ws.sharethis.com
- fonts.googleapis.com
- netdna.bootstrapcdn.com
- s.w.org
- seafreightshipping.com
- api.w.org
- cargomaster.com.au
- www.facebook.com
- www.abf.gov.au
- en.wikipedia.org
- www.containercontainer.com
- www.youtube.com
- www.safework.nsw.gov.au
- www.portbris.com.au
- www.townsville-port.com.au
- www.gpcl.com.au
- www.bic-code.org
- news.google.com
- www.fibre2fashion.com
- www.connexionfrance.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report