SUSPICIOUS — 408a2114177b0dcfc0120a23ca5baa82d7916c1f20812e37a65dd9a1b81a5e62
SUSPICIOUS — 408a2114177b0dcfc0120a23ca5baa82d7916c1f20812e37a65dd9a1b81a5e62 is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
408a2114177b0dcfc0120a23ca5baa82d7916c1f20812e37a65dd9a1b81a5e62 - SHA-1:
a0c79c6b3dcd991010d38a75c95e95b0de4bf03d - MD5:
a14293a7bcbd853b7f61cac41a1f9d76 - ssdeep:
384:yOOoe1QLg/mUYkOPVrJ9F0DXrogf+9pJ1we1QLg/7+1rFMo+3/nQrspaXjW8bQ/2:yOZWl/dYkOtr7PmWl/7+1rFMoApazfN - TLSH:
T17C33B50D4E146B9F4587461FB294BCAB44C598D7AFEDB3F58AC89F0FA804D70A00654B - Submitted as: 408a2114177b0dcfc0120a23ca5baa82d7916c1f20812e37a65dd9a1b81a5e62
- File type: html · Size: 49662 bytes
- Verdict: suspicious (54/100)
Detections (3 of 53 engines)
- Microsoft Defender: Exploit:VBS/MS06014.B
- Emsisoft (Emergency Kit): Trojan.StartPage.AAHD
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated vbscript script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://rozblog.com/temp/rang/like.png, http://matalmusic.rozblog.com, http://ebrahimkalate.rozblog.com - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://rozblog.com/temp/rang/like.png
- http://matalmusic.rozblog.com
- http://ebrahimkalate.rozblog.com
- http://online-shop.rozblog.com
- http://webhelp.rozfa.ir/
- http://webhelp.rozfa.ir/tag/%D8%AF%D8%B3%D8%AA%DA%AF%D8%A7%D9%87+%D9%87%D8%A7%D9%8A+%D8%AE%D9%86%DA%A9+%DA%A9%D9%86%D9%86%D8%AF%D9%87
- http://www.rozblog.com/theme/rozblog_v4/favi1.ico
- https://www.vistablog.ir
- http://www.rozsite.ir
- http://www.rozsite.ir.ir/update.php
- http://rozblog.com/temp/pro/ads_468.jpg
- http://webhelp.rozfa.ir/post/6
- http://online-shopiankala.com/ppicads/1282506318.jpg
- http://online-shopiankala.com/cat.php?id=1&
- http://online-shopiankala.com/subcat.php?zid=4&
- http://online-shopiankala.com/add2card.php?vendors=87020001&
- http://online-shopiankala.com/images/shop.gif
- http://webhelp.rozfa.ir/post/43
- http://174.142.7.129/%7Eadspics/ppicads/1282340301.jpg
- http://online-shopiankala.com/add2card.php?vendors=31130126&
- http://www.rozblog.com/
- http://rozblog.com/images/ads/logo_ads.png
- http://webhelp.rozfa.ir/forget
- http://webhelp.rozfa.ir/post/1
- http://webhelp.rozfa.ir/post/2
Embedded domains
- rozblog.com
- matalmusic.rozblog.com
- www.matalmusic.rozblog.com
- www.ebrahimkalate.rozblog.com
- ebrahimkalate.rozblog.com
- online-shop.rozblog.com
- www.online-shop.rozblog.com
- webhelp.rozfa.ir
- www.rozblog.com
- www.vistablog.ir
- www.rozsite.ir
- www.rozsite.ir.ir
- online-shopiankala.com
- cooldl.net
- www.googletagmanager.com
Embedded IP addresses
- 174.142.7.129
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report