SUSPICIOUS — 50298e62c71e0e9ce2f1b17db33099319535682b24dd71a47da095a4ba208671
SUSPICIOUS — 50298e62c71e0e9ce2f1b17db33099319535682b24dd71a47da095a4ba208671 is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
50298e62c71e0e9ce2f1b17db33099319535682b24dd71a47da095a4ba208671 - SHA-1:
ae15b0c4b17b4cb51a26f292272cff490c0245fb - MD5:
84281fc60b7b84c9317992f5ed99e318 - ssdeep:
1536:XDMLvlK6SJkXg6UdreYjXkEJiup6KwIo2r+OiqtN9fNEwMMdrZE:XYLvK6Ufj0WiuPrdtPwMdrZE - TLSH:
T190390A0F371535890CA186275AA89BD4D1C6D29BAA7780F6D4B36E44CC3CCE43C5A89F - Submitted as: 50298e62c71e0e9ce2f1b17db33099319535682b24dd71a47da095a4ba208671
- File type: html · Size: 86226 bytes
- Verdict: suspicious (54/100)
Detections (2 of 50 engines)
- Microsoft Defender: TrojanClicker:JS/Faceliker.M
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 54/100 is the fusion of 5 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 40 external host(s) at runtime (12 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css, http://fonts.googleapis.com/css?family=Oswald, http://ratu-maya.blogspot.com/favicon.ico - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (16 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
274 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- searchapp.bundleassets.example
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- settings-win.data.microsoft.com
- officeclient.microsoft.com
Embedded URLs
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css
- https://plus.google.com/101451808374516730985
- http://fonts.googleapis.com/css?family=Oswald
- http://ratu-maya.blogspot.com/favicon.ico
- http://ratu-maya.blogspot.com/2013/06/pasang-iklan-di-ratu-mayacom_16.html
- http://ratu-maya.blogspot.com/feeds/posts/default
- http://ratu-maya.blogspot.com/feeds/posts/default?alt=rss
- https://www.blogger.com/feeds/3738958643329850614/posts/default
- http://ratu-maya.blogspot.com/feeds/2724166350018066566/comments/default
- http://2.bp.blogspot.com/-J8m_ZNQ5NHI/UdMVgWZQGrI/AAAAAAAAAak/5wcXpST6d3k/s400/next.jpg
- http://2.bp.blogspot.com/-J8m_ZNQ5NHI/UdMVgWZQGrI/AAAAAAAAAak/5wcXpST6d3k/w1200-h630-p-k-no-nu/next.jpg
- http://4.bp.blogspot.com/-k2AsfzkzLjI/UAowRhYlhMI/AAAAAAAAAs4/xk4XZNfnbZs/s1600/blockquote.gif
- http://4.bp.blogspot.com/-zxPckZmJOK0/T_z_K1Tmd8I/AAAAAAAAApw/G2A5cq2Rj88/s77/noImageAvailable.jpg
- http://free-files.googlecode.com/files/Related-Post-Thumb.js
- http://adithya.googlecode.com/files/Apctrl%2Bu.js
- https://www.blogger.com/dyn-css/authorization.css?targetBlogID=3738958643329850614&
- http://ratu-maya.blogspot.com/
- https://www.blogger.com
- https://apis.google.com/js/plusone.js
- http://www.sundulbet.com/
- http://www.infobookie.net/adv/sundulbet.gif
- http://firstbola.com/
- http://4.bp.blogspot.com/-DEFWcBKZOsw/UcwDNv6-sEI/AAAAAAAAACo/ft8ahaRA-GA/s1600/728.gif
- http://www.rumahtaruhan88.com/
- http://www.infobookie.net/adv/rt88.gif
Embedded domains
- www.blogger.com
- plus.google.com
- fonts.googleapis.com
- ratu-maya.blogspot.com
- 2.bp.blogspot.com
- gmail.com
- 4.bp.blogspot.com
- free-files.googlecode.com
- entry.link
- adithya.googlecode.com
- blogspot.com
- apis.google.com
- pagead2.googlesyndication.com
- www.sundulbet.com
- www.infobookie.net
- firstbola.com
- www.rumahtaruhan88.com
- www.afb88.com
- www.saranapoker.com
- www.sarana303.com
- obatkuat-plus.blogspot.com
- lh6.googleusercontent.com
- www.obatkuatbogor.com
- alamatkonyol.com
- dimanja.info
Embedded IP addresses
- 20.184.175.21
- 52.123.252.216
- 40.84.85.40
- 52.110.12.21
- 135.233.95.144
- 20.184.175.9
- 20.42.179.192
- 20.112.250.133
- 172.178.240.162
- 162.159.142.9
- 52.110.12.25
- 4.247.188.233
- 4.230.171.124
- 20.247.185.124
- 20.42.65.94
- 172.66.2.5
- 172.178.240.163
- 52.110.12.10
- 85.210.196.11
- 52.123.252.198
- 20.184.175.7
- 52.110.12.47
- 57.155.101.212
- 20.247.184.197
- 72.153.5.136
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report