SUSPICIOUS — 4089e7a65b1df2d9be13c0462dafe0b713cec69641a214a7fcb6ca1a62525847
SUSPICIOUS — 4089e7a65b1df2d9be13c0462dafe0b713cec69641a214a7fcb6ca1a62525847 is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
4089e7a65b1df2d9be13c0462dafe0b713cec69641a214a7fcb6ca1a62525847 - SHA-1:
74d87a2a9b7f2a6907ea8da596a8d4005b6cb982 - MD5:
4a97452f76495db177f7b05cba24aa54 - ssdeep:
6144:pYsMYod+X3oI+Y/sMYod+X3oI+YLsMYod+X3oI+YQ:A5d+X3F5d+X315d+X3+ - TLSH:
T13848B0955072E28F0917AB9B621F769CDE5EF0E1420B3EC0559ABB8B0C29540FF424E7 - Submitted as: 4089e7a65b1df2d9be13c0462dafe0b713cec69641a214a7fcb6ca1a62525847
- File type: html · Size: 373969 bytes
- Verdict: suspicious (54/100)
Detections (3 of 53 engines)
- Microsoft Defender: Virus:VBS/Ramnit.gen!C
- Emsisoft (Emergency Kit): Trojan.HTML.Ramnit.A
- Kaspersky (KVRT): Trojan-Dropper.VBS.Agent.bp
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated powershell script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://www.nsw88.com, https://hm.baidu.com/hm.js?3f59711b6e16a4e8b6d8758e7eb0d66b, http://yc.jbl22.com/Help/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd
- http://www.w3.org/1999/xhtml
- http://www.nsw88.com
- https://hm.baidu.com/hm.js?3f59711b6e16a4e8b6d8758e7eb0d66b
- http://yc.jbl22.com/Help/
- http://yc.jbl22.com/Help/Leaveword.aspx
- http://yc.jbl22.com/Helps/ContactUs.html
- http://yc.jbl22.com/Sitemap.html
- http://yc.jbl22.com/xinjianxiaoqu/dichanxiaoqujingguan.html
- http://yc.jbl22.com/Helps/jingguanshuichuligon.html
- http://yc.jbl22.com/project/
- http://yc.jbl22.com/yuchishejijianzaogon.shtml
- http://yc.jbl22.com/yuchiguolvqicai.shtml
- http://yc.jbl22.com/Agent/
- http://yc.jbl22.com/Helps/aboutus.html
- http://yc.jbl22.com/Projects/bieshujiatingjinggua.html
- http://yc.jbl22.com/bieshuanli.shtml
- http://bdimg.share.baidu.com/static/js/shell_v2.js?cdnversion=
- http://yc.jbl22.com/xianyoudichan/tingyuanyuchisheji.html
- http://www.jbl22.com/project/
- http://yc.jbl22.com
- http://yc.jbl22.com/Article/shundemaizongtingyua_1.html
- http://yc.jbl22.com/Article/biguiyuandengzongbie_1.html
- http://yc.jbl22.com/Article/gaodashangdeyuchishe_1.html
- http://yc.jbl22.com/Article/yuchishuifalvzenmeba_1.html
Embedded domains
- www.w3.org
- hotmail.com
- qq.com
- www.nsw88.com
- hm.baidu.com
- yc.jbl22.com
- bdimg.share.baidu.com
- www.jbl22.com
- www.miitbeian.gov.cn
- weibo.com
- t.qq.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report