MALICIOUS — 502341e1c2605c1e6c4b719ef0b831297ba2dcda07da2d6f87ad364d26cc80f4
MALICIOUS — 502341e1c2605c1e6c4b719ef0b831297ba2dcda07da2d6f87ad364d26cc80f4 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100), attributed to the Obfus family. 3 of 50 detection engines flagged it.
Identification
- SHA-256:
502341e1c2605c1e6c4b719ef0b831297ba2dcda07da2d6f87ad364d26cc80f4 - SHA-1:
446033459a513378d8fe281a2b001b2abeb05952 - MD5:
784ccd244030b5d151bb400a23a0e72a - ssdeep:
768:NbtinJC4JA5FYecAcUv1CVKhvaMeXIj6/tzs0WEDyRRgt:CgLHYecAcUv1CVKhvaMe1ss - TLSH:
T1E52CD60266B9398FD2864146D45654A9A4DAFCCF782176C2C7ACDF8B981CD70D0BD04F - Submitted as: 502341e1c2605c1e6c4b719ef0b831297ba2dcda07da2d6f87ad364d26cc80f4
- File type: html · Size: 25249 bytes
- Verdict: malicious (93/100) · Family: Obfus
Detections (3 of 50 engines)
- ClamAV (daily): Js.Trojan.Obfus-633
- Microsoft Defender: Trojan:JS/HideLink.A
- Kaspersky (KVRT): Trojan.JS.HideLink.a
Why this verdict
The malicious score of 93/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Js.Trojan.Obfus-633 (rule
Js.Trojan.Obfus-633) - engine signal, weight 0.90, confidence 0.95 - Obfuscated javascript script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://vtvtaxi.se/index.php/boka-fardmedel/9-uncategorised/modules/mod_vcnt/modules/mod_plimunnivoslider/themes/default/modules/mod_plimunnivoslider/css/modules/mod_plimunnivoslider/css/modules/mod_vcnt/mod_vcnt.css, http://vtvtaxi.se/index.php/component/search/?Itemid=468&, http://vtvtaxi.se/modules/mod_PlimunNivoSlider/themes/default/bullets.png - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd
- http://www.w3.org/1999/xhtml
- http://vtvtaxi.se/index.php/boka-fardmedel/9-uncategorised/modules/mod_vcnt/modules/mod_plimunnivoslider/themes/default/modules/mod_plimunnivoslider/css/modules/mod_plimunnivoslider/css/modules/mod_vcnt/mod_vcnt.css
- http://vtvtaxi.se/index.php/component/search/?Itemid=468&
- http://vtvtaxi.se/modules/mod_PlimunNivoSlider/themes/default/bullets.png
- http://vtvtaxi.se/modules/mod_PlimunNivoSlider/themes/default/arrows.png
- http://vtvtaxi.se/modules/mod_PlimunNivoSlider/js/jquery-1.6.1.min.js
- http://vtvtaxi.se/modules/mod_PlimunNivoSlider/js/jquery.nivo.slider.js
- https://cdn.jsdelivr.net/gh/fancyapps/fancybox@3.5.7/dist/jquery.fancybox.min.css
- https://static.hugedomains.com/css/hdv3-css/reboot.min.css
- https://static.hugedomains.com/css/hdv3-css/style.css?r=20201105a
- https://static.hugedomains.com/css/hdv3-css/responsive.css?r=20201105a
- https://www.google.com/recaptcha/api.js
- https://www.googletagmanager.com/gtag/js?id=UA-7117339-4
- https://static.hugedomains.com/images/hdv3-img/logo.png
- https://static.hugedomains.com/images/hdv3-img/phone-icon.png
- http://www.hugedomains.com/domain_profile.cfm?d=plimun&e=com
- https://static.hugedomains.com/images/hdv3-img/care.png
- https://static.hugedomains.com/images/hdv3-img/guarant-footer.png
- https://static.hugedomains.com/images/hdv3-img/escrow.png
- https://static.hugedomains.com/images/hdv3-img/geo.png
- https://static.hugedomains.com/js/hdv3-js/jquery.min.js
- https://static.hugedomains.com/js/hdv3-js/script.js
Embedded domains
- www.w3.org
- vtvtaxi.se
- el.store
- cdn.jsdelivr.net
- static.hugedomains.com
- www.google.com
- www.googletagmanager.com
- www.hugedomains.com
- statcounter.com
- c.statcounter.com
More Obfus samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report