SUSPICIOUS — 425450a99fb2ebbbf22b140ee2553588af341ff6f0820b70c03a7543100f9fe6
SUSPICIOUS — 425450a99fb2ebbbf22b140ee2553588af341ff6f0820b70c03a7543100f9fe6 is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 1 of 53 detection engines flagged it.
Identification
- SHA-256:
425450a99fb2ebbbf22b140ee2553588af341ff6f0820b70c03a7543100f9fe6 - SHA-1:
0794cc0dfa5c0f324fa3dcf83b1017e727ca4ab9 - MD5:
471f70b76eb99a8cd205108fa1f83e0a - ssdeep:
1536:Grst13MxFH9zDinDo0IHdPoEfaLt4ps3M0cQFU4/6wldqA7idUz:Cst13MxFHBftPoEfaiYM0cQFUM6wldqk - TLSH:
T10038B51665D6068A84A40021E8AC807491D5BF5F983024DAE6BADF0DDC7CF79C1B98EF - Submitted as: 425450a99fb2ebbbf22b140ee2553588af341ff6f0820b70c03a7543100f9fe6
- File type: html · Size: 76720 bytes
- Verdict: suspicious (54/100)
Detections (1 of 53 engines)
- Microsoft Defender: Trojan:HTML/Redirector.SLYA!MTB
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://ogp.me/ns#, http://gmpg.org/xfn/11, https://probengg.com/xmlrpc.php - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://ogp.me/ns#
- http://gmpg.org/xfn/11
- https://probengg.com/xmlrpc.php
- http://cdnjs.cloudflare.com/ajax/libs/html5shiv/3.7/html5shiv.js
- https://yoast.com/wordpress/plugins/seo/
- https://probengg.com/
- https://schema.org
- https://probengg.com/#website
- https://probengg.com/feed/
- https://probengg.com/comments/feed/
- https://probengg.com/wp-content/plugins/LayerSlider/static/layerslider/css/layerslider.css?ver=6.5.7
- https://probengg.com/wp-includes/css/dist/block-library/style.min.css?ver=5.0.14
- https://probengg.com/wp-content/plugins/commercegurus-toolkit/css/cg_toolkit.css?ver=5.0.14
- https://probengg.com/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=5.1.1
- https://probengg.com/wp-content/plugins/revslider/public/assets/css/settings.css?ver=5.4.3.1
- https://probengg.com/wp-content/themes/fintech/style.css?ver=5.0.14
- https://probengg.com/wp-content/plugins/js_composer/assets/lib/bower/font-awesome/css/font-awesome.min.css?ver=5.6
- https://probengg.com/wp-content/themes/fintech/css/ionicons.css?ver=5.0.14
- https://probengg.com/wp-content/themes/fintech/css/animate.css?ver=5.0.14
- https://probengg.com/wp-content/themes/fintech/inc/core/bootstrap/dist/css/bootstrap.min.css?ver=5.0.14
- https://probengg.com/wp-content/themes/fintech/css/commercegurus.css?ver=5.0.14
- https://probengg.com/wp-content/themes/fintech/css/responsive.css?ver=5.0.14
- https://probengg.com/wp-content/plugins/js_composer/assets/css/js_composer.min.css?ver=5.6
- https://fonts.googleapis.com/css?family=Source+Sans+Pro%3A200%2C300%2C400%2C600%2C700%2C900%2C200italic%2C300italic%2C400italic%2C600italic%2C700italic%2C900italic%7CNothing+You+Could+Do%3A400%7CPoppins%3A300%2C400%2C500%2C600%2C700&
- https://probengg.com/wp-content/plugins/LayerSlider/static/layerslider/js/greensock.js?ver=1.19.0
Embedded domains
- ogp.me
- gmpg.org
- probengg.com
- cdnjs.cloudflare.com
- yoast.com
- schema.org
- fonts.googleapis.com
- s.w.org
- layerslider.kreaturamedia.com
- api.w.org
- gmail.com
- fintechdata.commercegurus.com
Embedded IP addresses
- 5.4.3.1
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report