SUSPICIOUS — 50264756b385609ebb4516d20023528a7b0cc59f71845df7e2f47f7c072f765c
SUSPICIOUS — 50264756b385609ebb4516d20023528a7b0cc59f71845df7e2f47f7c072f765c is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
50264756b385609ebb4516d20023528a7b0cc59f71845df7e2f47f7c072f765c - SHA-1:
ac5d9fa8d24545201a499a6b7eee866e3a4c3a1d - MD5:
0ab4bce68e1a1f9499db475642fc60c3 - ssdeep:
1536:HpA3St91SpPWv98zrN4lsVA13JYmohPNL4ct2RD:5t9GWvWzrN4lsVA13JYmohPBt2RD - TLSH:
T11C3A93697B5A7A0A2450C147A4AC1EE483D35326E733C0FAF0B377858269DB5BC4F942 - Submitted as: 50264756b385609ebb4516d20023528a7b0cc59f71845df7e2f47f7c072f765c
- File type: html · Size: 94074 bytes
- Verdict: suspicious (54/100)
Detections (2 of 50 engines)
- Microsoft Defender: TrojanClicker:JS/Faceliker.M
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css, http://test-ver30.blogspot.com/favicon.ico, http://test-ver30.blogspot.com/search/label/h%C3%A0i%20h%C6%B0%E1%BB%9Bc - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.google.com/2005/gml/b
- http://www.google.com/2005/gml/data
- http://www.google.com/2005/gml/expr
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css
- http://test-ver30.blogspot.com/favicon.ico
- http://test-ver30.blogspot.com/search/label/h%C3%A0i%20h%C6%B0%E1%BB%9Bc
- http://test-ver30.blogspot.com/feeds/posts/default
- http://test-ver30.blogspot.com/feeds/posts/default?alt=rss
- https://www.blogger.com/feeds/4183005100029960026/posts/default
- https://www.blogger.com/profile/10614454538142249828
- http://dl.dropbox.com/u/52283085/nguoikechuyen/jquery.min.js
- https://dl.dropbox.com/u/68633188/ngkchuyen/blogradio.in/v2.js
- https://dl.dropbox.com/u/68633188/ngkchuyen/blogradio.in/thumbail.js
- http://kainy.googlecode.com/svn/trunk/ie6/killie6.utf-8.js
- http://html5shim.googlecode.com/svn/trunk/html5.js
- http://www.share123.vn/
- http://4.bp.blogspot.com/-6s0jYiq2kX4/T5YSVl4wSsI/AAAAAAAADXM/gdymNoSooxM/s1600/topbar.png
- http://1.bp.blogspot.com/-Rp8rW44vBO0/T5YSifkGFwI/AAAAAAAADXU/wqFKrKhSFys/s1600/topbar_line.png
- http://2.bp.blogspot.com/-PX0eZZbqg1s/T5YSuDtGRMI/AAAAAAAADXo/ULb9gwAwTRU/s1600/bg.png
- http://4.bp.blogspot.com/-i3qyOgynd8A/T5YStfcbM3I/AAAAAAAADXg/tQYjnjSVBQg/s1600/Tline.png
- http://1.bp.blogspot.com/-dC1Rd3grC0U/T5YSyHkhHhI/AAAAAAAADYQ/60NisCYsfV8/s1600/list.png
- http://2.bp.blogspot.com/-s0OZ8DlECG4/T5YSrUsFj2I/AAAAAAAADXc/Cdk3iGtYs44/s1600/Example.png
- http://3.bp.blogspot.com/-qM4EA4No7N4/T5YSz1GS8mI/AAAAAAAADYk/raYZEBPBVqE/s1600/mainbg.png
- http://1.bp.blogspot.com/-YYIrHSgtiVk/T5YS1qoH7UI/AAAAAAAADYo/SE7vaAmgf3A/s1600/pixel.png
Embedded domains
- www.w3.org
- www.google.com
- www.blogger.com
- test-ver30.blogspot.com
- truyenv2-manhdat.blogspot.com
- google-analytics.com
- dl.dropbox.com
- blogradio.in
- kainy.googlecode.com
- html5shim.googlecode.com
- gmail.com
- 4.bp.blogspot.com
- 1.bp.blogspot.com
- 2.bp.blogspot.com
- 3.bp.blogspot.com
- lh3.googleusercontent.com
- nguyenhuytap.googlecode.com
- blogspot.com
- apis.google.com
- pagead2.googlesyndication.com
- lh5.googleusercontent.com
- modeone.net
- entry.link
- lh4.googleusercontent.com
- rilwis.googlecode.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report