SUSPICIOUS — 562971644ffe3ab5868a001baf4563c6ac0ab6f238e14628142ef485d61fcb3c
SUSPICIOUS — 562971644ffe3ab5868a001baf4563c6ac0ab6f238e14628142ef485d61fcb3c is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
562971644ffe3ab5868a001baf4563c6ac0ab6f238e14628142ef485d61fcb3c - SHA-1:
79f40cbf277e8a5b838dea557a53af747a7fd226 - MD5:
b5e0777817e6be2892ce653d712823d8 - ssdeep:
384:UIhHDzVbbMz0cLFIt+Ywt1t4yS0wfgTXSUh5fBhq:UWjq04Fbi4TXSUhtBhq - TLSH:
T17226B61DEA061EAF9586D40DE814CDACB8CAF5CF197590C4CECE9F588C888F5D849362 - Submitted as: 562971644ffe3ab5868a001baf4563c6ac0ab6f238e14628142ef485d61fcb3c
- File type: html · Size: 14587 bytes
- Verdict: suspicious (54/100)
Detections (2 of 53 engines)
- Microsoft Defender: Trojan:HTML/Faceliker.AP!MTB
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://www.vvchem.com, http://www.vvchem.com/products/, http://www.vvchem.com/sell/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd
- http://www.w3.org/1999/xhtml
- http://www.vvchem.com
- http://www.vvchem.com/products/
- http://www.vvchem.com/sell/
- http://www.vvchem.com/buy/
- http://www.vvchem.com/suppliers/
- http://www.vvchem.com/login.jsp
- http://www.vvchem.com/reg.jsp
- https://pagead2.googlesyndication.com/pagead/js/adsbygoogle.js
- http://www.vvchem.com/cas-201/2011-66-7.html
- http://www.vvchem.com/structure/cas-201/2011-66-7.png
- http://www.vvchem.com/dictionary/en/
- http://beian.miit.gov.cn
- http://s23.cnzz.com/stat.php?id=3543253&web_id=3543253&show=pic
- https://hm.baidu.com/hm.js?2f78e49beb4702631266e0f0a72433f5
Embedded domains
- www.w3.org
- www.vvchem.com
- pagead2.googlesyndication.com
- beian.miit.gov.cn
- s23.cnzz.com
- hm.baidu.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report