SUSPICIOUS — 3f7ec987a294f8322a72b5768ec76d9666b9351b3927ba0eb92151b92776ace2
SUSPICIOUS — 3f7ec987a294f8322a72b5768ec76d9666b9351b3927ba0eb92151b92776ace2 is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 0 of 54 detection engines flagged it.
Identification
- SHA-256:
3f7ec987a294f8322a72b5768ec76d9666b9351b3927ba0eb92151b92776ace2 - SHA-1:
af5275c20c385b7e21efe79309c945f0e09b0087 - MD5:
ab69e772611ab60a0f8d325223163020 - ssdeep:
1536:rmQRuUkHO1TWXGPr71ZQcgWuFo09rJ3I4mCkkq7sc9Acc9AC9:rmQRuUkHO1TWXGPr71ZQcgWuFoerJ3Ii - TLSH:
T12F37408593457EEF929C49A6F5C5885C48E0F2DFD83245B8C680DB5AF881FA1A0C94CF - Submitted as: 3f7ec987a294f8322a72b5768ec76d9666b9351b3927ba0eb92151b92776ace2
- File type: html · Size: 71724 bytes
- Verdict: suspicious (54/100)
Detections (0 of 54 engines)
No engine flagged this sample.
Why this verdict
The suspicious score of 54/100 is the fusion of 4 weighted signals:
- Obfuscated javascript script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 1 external host(s) and 5 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://ogp.me/ns#, http://purl.org/rss/1.0/modules/content/, http://purl.org/dc/terms/ - static signal, weight 0.35, confidence 0.60
- Extracted generic config (15 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
280 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- v10.events.data.microsoft.com
- edge.microsoft.com
- ctldl.windowsupdate.com
- time.windows.com
Embedded URLs
- http://ogp.me/ns#
- http://purl.org/rss/1.0/modules/content/
- http://purl.org/dc/terms/
- http://xmlns.com/foaf/0.1/
- http://www.w3.org/2000/01/rdf-schema#
- http://rdfs.org/sioc/ns#
- http://rdfs.org/sioc/types#
- http://www.w3.org/2004/02/skos/core#
- http://www.w3.org/2001/XMLSchema#
- https://dop.gov.mm/sites/dop.gov.mm/files/favicons/favicon.ico
- https://www.drupal.org
- https://dop.gov.mm/en/publication-category/township-report
- https://dop.gov.mm/en/taxonomy/term/50
- https://dop.gov.mm/sites/dop.gov.mm/files/uncharted_ogfront_1200x630.jpg
- https://dop.gov.mm/modules/system/system.base.css?qw9r77
- https://dop.gov.mm/modules/system/system.menus.css?qw9r77
- https://dop.gov.mm/modules/system/system.messages.css?qw9r77
- https://dop.gov.mm/modules/system/system.theme.css?qw9r77
- https://dop.gov.mm/sites/dop.gov.mm/libraries/chosen/chosen.css?qw9r77
- https://dop.gov.mm/sites/dop.gov.mm/modules/chosen/css/chosen-drupal.css?qw9r77
- https://dop.gov.mm/modules/comment/comment.css?qw9r77
- https://dop.gov.mm/sites/dop.gov.mm/modules/date/date_api/date.css?qw9r77
- https://dop.gov.mm/sites/dop.gov.mm/modules/date/date_popup/themes/datepicker.1.7.css?qw9r77
- https://dop.gov.mm/modules/field/theme/field.css?qw9r77
- https://dop.gov.mm/sites/dop.gov.mm/modules/logintoboggan/logintoboggan.css?qw9r77
Embedded domains
- ogp.me
- purl.org
- xmlns.com
- www.w3.org
- rdfs.org
- www.drupal.org
- code.jquery.com
- www.google-analytics.com
- connect.facebook.net
- www.facebook.com
- gmail.com
- myanmar.unfpa.org
- widget.supercounters.com
- www.supercounters.com
- dop.gov.mm
- www.dopredatam.gov.mm
- www.moe.gov.mm
- mohs.gov.mm
- www.mol.gov.mm
- evisa.moip.gov.mm
- dop.gov
Embedded IP addresses
- 52.168.117.169
- 20.247.185.124
- 52.123.252.225
- 4.230.171.124
- 4.150.223.109
- 20.42.73.27
- 52.110.12.4
- 40.84.85.40
- 184.84.165.171
- 52.110.12.31
- 52.110.12.8
- 52.148.114.188
- 72.145.35.97
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report