SUSPICIOUS — 41a2ecf1bd657a37704f0d981fc78366949a29296214236cc2155611a95d4df2
SUSPICIOUS — 41a2ecf1bd657a37704f0d981fc78366949a29296214236cc2155611a95d4df2 is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 0 of 54 detection engines flagged it.
Identification
- SHA-256:
41a2ecf1bd657a37704f0d981fc78366949a29296214236cc2155611a95d4df2 - SHA-1:
ee35f0fdf4782ea9e73819168418a8e73595fda1 - MD5:
f9c2fdb4001e2a5a82782a8cb1a6fe8a - ssdeep:
1536:orbu8utmK1SW4bwZsRK5G/ocM0MrNtf6CQyhmiqPtg1A23HgELCrlwxYBNx0ExlF:obu8utm7W4bwZsRK5Gqtf6CQblg1d3H+ - TLSH:
T15C33E730E2E27F6341C44C40E58844A48464FE5FB63674A58A35FF87B41EE60987EA8F - Submitted as: 41a2ecf1bd657a37704f0d981fc78366949a29296214236cc2155611a95d4df2
- File type: html · Size: 50515 bytes
- Verdict: suspicious (54/100)
Detections (0 of 54 engines)
No engine flagged this sample.
Why this verdict
The suspicious score of 54/100 is the fusion of 4 weighted signals:
- Obfuscated javascript script: dynamic-exec (layers: char-code) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 4 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://necckaduna.com.ng/feed/, https://necckaduna.com.ng/comments/feed/, https://necckaduna.com.ng/wp-includes/css/dist/block-library/style.min.css?ver=5.7.4 - static signal, weight 0.35, confidence 0.60
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
279 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- odc.officeapps.live.com
- www.msn.com
- www.bing.com
- assets.msn.com
- v10.events.data.microsoft.com
- edge.microsoft.com
- time.windows.com
- settings-win.data.microsoft.com
Embedded URLs
- https://necckaduna.com.ng/feed/
- https://necckaduna.com.ng/comments/feed/
- https://necckaduna.com.ng/wp-includes/css/dist/block-library/style.min.css?ver=5.7.4
- https://necckaduna.com.ng/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=4.9.2
- https://necckaduna.com.ng/wp-content/plugins/kiwi-social-share/assets/vendors/icomoon/style.css?ver=2.0.14
- https://necckaduna.com.ng/wp-content/plugins/payment-forms-for-paystack/public/css/pff-paystack-style.css?ver=2.0.0
- https://necckaduna.com.ng/wp-content/plugins/payment-forms-for-paystack/public/css/font-awesome.min.css?ver=2.0.0
- https://necckaduna.com.ng/wp-content/plugins/wp-live-chat-support/css/wplcstyle.css?ver=8.0.30
- https://necckaduna.com.ng/wp-content/plugins/wp-live-chat-support/images/iconRetina.png
- https://necckaduna.com.ng/wp-content/plugins/wp-live-chat-support/images/iconCloseRetina.png
- https://necckaduna.com.ng/wp-content/plugins/wp-live-chat-support/images/bg/cloudy.jpg
- https://necckaduna.com.ng/wp-content/plugins/wp-live-chat-support/css/themes/theme-default.css?ver=8.0.30
- https://necckaduna.com.ng/wp-content/plugins/wp-live-chat-support/css/themes/modern.css?ver=8.0.30
- https://necckaduna.com.ng/wp-content/plugins/wp-live-chat-support/css/themes/position-bottom-right.css?ver=8.0.30
- https://necckaduna.com.ng/wp-content/plugins/wp-live-chat-support/includes/blocks/wplc-chat-box/wplc_gutenberg_template_styles.css?ver=5.7.4
- https://necckaduna.com.ng/wp-content/plugins/wp-live-chat-support/css/wplc_gif_integration.css?ver=5.7.4
- https://necckaduna.com.ng/wp-content/themes/medzone-lite/style.css?ver=5.7.4
- https://necckaduna.com.ng/wp-content/themes/medzone-lite/assets/vendors/font-awesome/css/font-awesome.min.css?ver=5.7.4
- https://necckaduna.com.ng/wp-content/themes/medzone-lite/assets/vendors/bxslider/jquery.bxslider.css?ver=5.7.4
- https://necckaduna.com.ng/wp-content/themes/medzone-lite/assets/vendors/slick/slick.css?ver=5.7.4
- https://necckaduna.com.ng/wp-content/themes/medzone-lite/assets/css/main.css?ver=1.2.3
- https://necckaduna.com.ng/wp-content/themes/medzone-lite/assets/css/overrides.css?ver=5.7.4
- https://necckaduna.com.ng/wp-includes/js/jquery/jquery.min.js?ver=3.5.1
- https://necckaduna.com.ng/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.3.2
- https://necckaduna.com.ng/wp-content/plugins/wp-live-chat-support/js/jquery-cookie.js?ver=5.7.4
Embedded domains
- js.paystack.co
- fonts.googleapis.com
- s.w.org
- www.gravatar.com
- api.w.org
- www.schema.org
- facebook.com
- twitter.com
- linkedin.com
- www.linkedin.com
- necckaduna.com.ng
- google.com
Embedded IP addresses
- 40.79.167.9
- 52.253.84.76
- 4.230.171.124
- 52.168.117.170
- 40.79.150.121
- 85.210.193.152
- 52.110.12.48
- 52.110.12.16
- 52.148.114.188
- 72.153.5.137
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report