MALICIOUS — 3addb573b14949015db80afcc67b3286a370a6352c2fcdb37cd9e869fa3ebd83
MALICIOUS — 3addb573b14949015db80afcc67b3286a370a6352c2fcdb37cd9e869fa3ebd83 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
3addb573b14949015db80afcc67b3286a370a6352c2fcdb37cd9e869fa3ebd83 - SHA-1:
da12caf2d502dc04a1fdd11f770254c9a409663f - MD5:
c825727bc584457658ac1bbafa3dd42a - ssdeep:
6144:ksMYod+X3oI+YXsMYod+X3oI+YPYsMYod+X3oI+YW:y5d+X355d+X3Vm5d+X3c - TLSH:
T1F448AF959071D18F0907A797A22F728CCF6FE4D1820B3B81555ABB8F092A540FF924E7 - Submitted as: 3addb573b14949015db80afcc67b3286a370a6352c2fcdb37cd9e869fa3ebd83
- File type: html · Size: 353462 bytes
- Verdict: malicious (93/100)
Detections (4 of 50 engines)
- ClamAV (daily): Win.Trojan.Agent-36393
- Microsoft Defender: Virus:VBS/Ramnit.gen!A
- Emsisoft (Emergency Kit): Trojan.Dropper.VBS.Q
- Kaspersky (KVRT): Trojan-Dropper.VBS.Agent.bp
Why this verdict
The malicious score of 93/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Agent-36393 (rule
Win.Trojan.Agent-36393) - engine signal, weight 0.90, confidence 0.95 - Obfuscated vbscript script: dynamic-exec (layers: base64) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://zg7.com/, http://zg7.com/forum.php, http://zg7.com/template/jingyun_toutiao/zhanzhuaicn_img/common/bbs.ico - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd
- http://www.w3.org/1999/xhtml
- http://zg7.com/
- http://zg7.com/forum.php
- http://zg7.com/template/jingyun_toutiao/zhanzhuaicn_img/common/bbs.ico
- http://zg7.com/source/plugin/austgl_audio/player/APlayer.min.css
- http://zg7.com/source/plugin/austgl_audio/player/APlayer.min.js
- https://www.zg7.com/
- http://www.discuz.net
- http://beian.miit.gov.cn/
- http://www.comsenz.com
- http://wpa.qq.com/msgrd?V=3&
- http://zg7.com/home.php?mod=misc%26ac=sendmail%26rand=1636246326
Embedded domains
- www.w3.org
- zg7.com
- www.zg7.com
- www.discuz.net
- beian.miit.gov.cn
- www.comsenz.com
- wpa.qq.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report