MALICIOUS — 4e2bbf3f2471596a1ff50a136a9a936350d87c0cae02e1ffbc5b36ed542e2b28
MALICIOUS — 4e2bbf3f2471596a1ff50a136a9a936350d87c0cae02e1ffbc5b36ed542e2b28 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the TrojanClicker family. 2 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4e2bbf3f2471596a1ff50a136a9a936350d87c0cae02e1ffbc5b36ed542e2b28 - SHA-1:
e937742211cf921e664eb323c61574dfb82e7fee - MD5:
6c378eafecb0e491b4f2bb492cbd771e - ssdeep:
1536:l5/W+PCg4sWsLY+Coysc+OI0IscSptQ3wkABcQbZkAX9TgfyIPmFMxZPdVfx3TQU:l5gkAmGZkAtTgfyumFMxZPdVfx3TNkAz - TLSH:
T1713A1A17F6167F9F88E09117249C26E460C58AD7E53322F1CAE7AF888C6CC60AC5D527 - Submitted as: 4e2bbf3f2471596a1ff50a136a9a936350d87c0cae02e1ffbc5b36ed542e2b28
- File type: html · Size: 98284 bytes
- Verdict: malicious (92/100) · Family: TrojanClicker
Detections (2 of 54 engines)
- Microsoft Defender: TrojanClicker:JS/Faceliker.D
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 92/100 is the fusion of 8 weighted signals:
- Microsoft Defender flagged TrojanClicker:JS/Faceliker.D (rule
TrojanClicker:JS/Faceliker.D) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 34 external host(s) and 12 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1667664774-css_bundle_v2.css, http://chikochannel.blogspot.com/favicon.ico, http://chikochannel.blogspot.com/search/label/hung%20nguyen%20page - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (13 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
15952 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- 1.0.240.10.in-addr.arpa.
- 76.0.240.10.in-addr.arpa.
- 172.30.101.151.in-addr.arpa.
- 209.52.40.23.in-addr.arpa.
- tas02.sls.update.microsoft.com
- v10.events.data.microsoft.com
- d.1.d.1.c.4.2.1.4.9.5.2.6.e.8.b.0.0.0.0.0.0.0.0.0.0.0.0.0.8.e.f.ip6.arpa.
- 104.223.150.4.in-addr.arpa.
- 61.240.178.74.in-addr.arpa.
- 251.0.0.224.in-addr.arpa.
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.google.com/2005/gml/b
- http://www.google.com/2005/gml/data
- http://www.google.com/2005/gml/expr
- https://www.blogger.com/static/v1/widgets/1667664774-css_bundle_v2.css
- http://chikochannel.blogspot.com/favicon.ico
- http://chikochannel.blogspot.com/search/label/hung%20nguyen%20page
- http://chikochannel.blogspot.com/feeds/posts/default
- http://chikochannel.blogspot.com/feeds/posts/default?alt=rss
- https://draft.blogger.com/feeds/2790403288067363484/posts/default
- https://www.blogger.com/static/v1/jsbin/403901366-ieretrofit.js
- http://chikochannel.blogspot.com/
- http://homhinhvl.blogspot.com/
- https://plus.google.com/117308023186718035063/
- https://plus.google.com/+MuzikersBlogspotchiko/
- http://code.jquery.com/jquery-latest.js
- https://googledrive.com/host/0B9xIFobSQEOdRld0bHM4ZXItczA/finger.gif
- http://s.haivl.com/content/images/logo_40.png
- http://i1251.photobucket.com/albums/hh542/vctpro/upload_icon.png
- http://i1251.photobucket.com/albums/hh542/vctpro/down_icon.png
- http://i1251.photobucket.com/albums/hh542/vctpro/exclamation.png
- http://i1251.photobucket.com/albums/hh542/vctpro/information.png
- http://s.haivl.com/content/images/admin/icons/tick_circle.png
- http://i1251.photobucket.com/albums/hh542/vctpro/cross_circle.png
- http://i1251.photobucket.com/albums/hh542/vctpro/cross_grey_small.png
Embedded domains
- www.w3.org
- www.google.com
- www.blogger.com
- chikochannel.blogspot.com
- draft.blogger.com
- homhinhvl.blogspot.com
- gmail.com
- plus.google.com
- code.jquery.com
- googledrive.com
- djdownload.biz
- s.haivl.com
- i1251.photobucket.com
- cuoi-muzikers.blogspot.com
- nguyenhuytap.googlecode.com
- www.facebook.com
- blogspot.com
- www.tinkhuyenmai.ga
- schema.org
- i1.ytimg.com
- www.youtube.com
- 2.bp.blogspot.com
- muzikers.blogspot.com
- feeds.feedburner.com
- twitter.com
Embedded IP addresses
- 85.210.196.11
- 40.84.85.40
- 4.247.188.233
- 74.178.240.61
- 4.150.223.104
- 52.138.229.67
- 4.150.223.114
- 20.42.73.31
- 20.42.179.204
- 52.123.252.216
- 40.79.150.121
- 48.211.4.16
- 40.84.97.4
- 72.145.35.111
- 52.148.114.188
- 40.79.163.154
- 52.168.112.67
- 20.184.175.14
- 4.150.223.109
- 72.145.35.97
- 20.184.175.15
- 4.150.223.102
- 74.178.76.128
- 135.234.160.245
- 4.247.188.224
More TrojanClicker samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report