MALICIOUS — 40889e60c787095f6f74fb51a7431d3bbcd64054b6dae6472300169857e358b1
MALICIOUS — 40889e60c787095f6f74fb51a7431d3bbcd64054b6dae6472300169857e358b1 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100), attributed to the Redirector family. 3 of 53 detection engines flagged it.
Identification
- SHA-256:
40889e60c787095f6f74fb51a7431d3bbcd64054b6dae6472300169857e358b1 - SHA-1:
0a0904a41d37df4fa22000a78010ac82283e645a - MD5:
a3b0ee5062ed2b53fcaa03e9c7ccbef5 - ssdeep:
384:O7wW/Jg1NM+wWnhS3Z0WPq9hSYiRZaaGLQGjVBDBdllGJoR7Ea7iqqr9d:uJg1NKwgy3iRwTfDB+GA - TLSH:
T1A42D51742F1EB94F20D0802FB5AC1DD8C19987AAF677C4F5E567B6809036DA0BC0E582 - Submitted as: 40889e60c787095f6f74fb51a7431d3bbcd64054b6dae6472300169857e358b1
- File type: html · Size: 29302 bytes
- Verdict: malicious (87/100) · Family: Redirector
Detections (3 of 53 engines)
- Microsoft Defender: Trojan:JS/Redirector.PP
- Emsisoft (Emergency Kit): Trojan.Agent.EQVI
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 87/100 is the fusion of 4 weighted signals:
- Microsoft Defender flagged Trojan:JS/Redirector.PP (rule
Trojan:JS/Redirector.PP) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Agent.EQVI (rule
Trojan.Agent.EQVI) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css, http://designcreate.blogspot.com/favicon.ico, http://designcreate.blogspot.com/search/label/programas - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.google.com/2005/gml/b
- http://www.google.com/2005/gml/data
- http://www.google.com/2005/gml/expr
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css
- http://designcreate.blogspot.com/favicon.ico
- http://designcreate.blogspot.com/search/label/programas
- http://designcreate.blogspot.com/feeds/posts/default
- http://designcreate.blogspot.com/feeds/posts/default?alt=rss
- https://www.blogger.com/feeds/381108556013264675/posts/default
- https://www.blogger.com/dyn-css/authorization.css?targetBlogID=381108556013264675&
- https://dl.dropbox.com/u/8497803/blog-do-shot/css/style.css.css
- https://apis.google.com/js/plusone.js
- http://www.hackerinsano.net/
- http://4.bp.blogspot.com/_LTIhDm0Jos0/TGLEPLVPVoI/AAAAAAAAA2E/_znfO9g3DNM/S1600-R/banner.png
- http://el-project.webs.com/criandomubr/imgs/down.gif
- http://www.ciadosmubr.com/2009/12/criar-servidor-de-mu-online.html
- http://designcreate.blogspot.com/search/label/Avisos
- http://designcreate.blogspot.com/search/label/Blogger
- http://designcreate.blogspot.com/search/label/Brushes
- http://designcreate.blogspot.com/search/label/Curso
- http://designcreate.blogspot.com/search/label/Design
- http://designcreate.blogspot.com/search/label/Dicas
- http://designcreate.blogspot.com/search/label/Editaveis
- http://designcreate.blogspot.com/search/label/Entrega%20De%20Banners
Embedded domains
- www.w3.org
- www.google.com
- www.blogger.com
- designcreate.blogspot.com
- www.roxcreate.com
- blogspot.com
- dl.dropbox.com
- apis.google.com
- pagead2.googlesyndication.com
- www.hackerinsano.net
- 4.bp.blogspot.com
- el-project.webs.com
- www.ciadosmubr.com
- img801.imageshack.us
- www.reiofdowns.co.cc
- www.xdesiner.co.cc
- 1.bp.blogspot.com
- hipercreate.blogspot.com
- 2.bp.blogspot.com
- www.imperiodesign.co.cc
- www.pixyup.com
- speedtemplates.blogspot.com
- i54.tinypic.com
- i.imgur.com
- panicdesign.webs.com
More Redirector samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report