SUSPICIOUS — 502c6e91f7ea47e3fb914abb4774fa7129e82f2279da19c6cb26f330a8e1c7c3
SUSPICIOUS — 502c6e91f7ea47e3fb914abb4774fa7129e82f2279da19c6cb26f330a8e1c7c3 is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
502c6e91f7ea47e3fb914abb4774fa7129e82f2279da19c6cb26f330a8e1c7c3 - SHA-1:
b4af3a035840d86e4e30ecaab125aeb5b02a36a4 - MD5:
953d321f761f94ef3c64f22614daa7dc - ssdeep:
1536:ZWkADkAZckABKQbZkAXhTcr0IPGNMxZPdJXxPTQakAW+SOvFSupq8Lh/lo6ZrOeg:kkADkAikAIGZkARTcr0uGNMxZPdJXxPG - TLSH:
T1B0372C0F73113B5B89B4941556FD52E450CBC22B983366E9C8EBFE858C7CCA46C4D82A - Submitted as: 502c6e91f7ea47e3fb914abb4774fa7129e82f2279da19c6cb26f330a8e1c7c3
- File type: html · Size: 75037 bytes
- Verdict: suspicious (54/100)
Detections (2 of 50 engines)
- Microsoft Defender: flagged
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1667664774-css_bundle_v2.css, http://1.bp.blogspot.com/-miDISEVzUkc/UY-f1Bd_y0I/AAAAAAAAAo0/CskBfjOpJBw/s1600/favicon.ico, http://s.haivl.com/content/images/logo_smiley.jpg - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.google.com/2005/gml/b
- http://www.google.com/2005/gml/data
- http://www.google.com/2005/gml/expr
- https://www.blogger.com/static/v1/widgets/1667664774-css_bundle_v2.css
- http://1.bp.blogspot.com/-miDISEVzUkc/UY-f1Bd_y0I/AAAAAAAAAo0/CskBfjOpJBw/s1600/favicon.ico
- https://plus.google.com/u/0/101055844436873940439/about
- https://plus.google.com/u/0/101055844436873940439/posts
- http://s.haivl.com/content/images/logo_smiley.jpg
- http://s.haivl.com/content/images/logo_40.png
- http://s.haivl.com/content/images/upload_icon.png
- http://s.haivl.com/content/images/down_icon.png
- http://s.haivl.com/content/images/admin/icons/exclamation.png
- http://s.haivl.com/content/images/admin/icons/information.png
- http://s.haivl.com/content/images/admin/icons/tick_circle.png
- http://s.haivl.com/content/images/admin/icons/cross_circle.png
- http://s.haivl.com/content/images/admin/icons/cross_grey_small.png
- http://s.haivl.com/content/images/vote_icon.png
- http://s.haivl.com/content/images/view_icon.png
- http://s.haivl.com/content/images/comment_icon.png
- http://s.haivl.com/content/images/source_icon.png
- http://s.haivl.com/content/images/like_icon.png
- http://s.haivl.com/content/images/smile_icon.png
- http://s.haivl.com/content/images/prev_icon.png
- http://s.haivl.com/content/images/next_icon.png
Embedded domains
- www.w3.org
- www.google.com
- www.blogger.com
- 1.bp.blogspot.com
- djdownload.biz
- plus.google.com
- s.haivl.com
- nguyenhuytap.googlecode.com
- www.facebook.com
- blogspot.com
- rucrovl.blogspot.com
- rucro.net
- img1.blogblog.com
- schema.org
- resources.blogblog.com
- b.name
- 4.bp.blogspot.com
- 3.bp.blogspot.com
- www.hai24vn.com
- docs.google.com
- twitter.com
- platform.twitter.com
- fapfapvn.blogspot.com
- widgets.amung.us
- lh6.ggpht.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report