SUSPICIOUS — 57e9fcd5ad186925d0845baaec892c3844a9848a76f3c6d328de562c3c7de715
SUSPICIOUS — 57e9fcd5ad186925d0845baaec892c3844a9848a76f3c6d328de562c3c7de715 is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 1 of 50 detection engines flagged it.
Identification
- SHA-256:
57e9fcd5ad186925d0845baaec892c3844a9848a76f3c6d328de562c3c7de715 - SHA-1:
d0d830fbbf4dbe176dc32f5f3a08648a03a8cf61 - MD5:
0a96939ed77eb2e97ae5016fc4cb28f4 - ssdeep:
1536:/EH+w/vqUoDKLX8zOzQUCvE44444ePwgfbw9eQOsA6e8aJbJ7bS/bxY2lV28yD4a:/I1TqXmwgfbw9eeAD7bS/bxeX - TLSH:
T1DE380725F4971FFBC58C5511F0EAC8306282EEE798E05BD95388CF8D9818EA1E17C496 - Submitted as: 57e9fcd5ad186925d0845baaec892c3844a9848a76f3c6d328de562c3c7de715
- File type: html · Size: 82781 bytes
- Verdict: suspicious (54/100)
Detections (1 of 50 engines)
- Microsoft Defender: Trojan:JS/Redirector.FGL!MTB
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (layers: base64+char-code) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://texgazz.ru/favicon.svg, https://tex-gaz.online/wp-content/cache/autoptimize/css/autoptimize_47683c71b155bfb99680f271c2c5c6e6.css, https://ajax.googleapis.com/ajax/libs/webfont/1.5.3/webfont.js - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://texgazz.ru/favicon.svg
- https://tex-gaz.online/wp-content/uploads/2019/03/favicon.png
- https://tex-gaz.online/wp-content/cache/autoptimize/css/autoptimize_47683c71b155bfb99680f271c2c5c6e6.css
- https://ajax.googleapis.com/ajax/libs/webfont/1.5.3/webfont.js
- https://tex-gaz.online/
- https://schema.org
- https://tex-gaz.online/#website
- https://tex-gaz.online/#webpage
- https://tex-gaz.online/amp/
- https://tex-gaz.online/feed/
- https://tex-gaz.online/comments/feed/
- https://tex-gaz.online/home/feed/
- https://api.w.org/
- https://tex-gaz.online/wp-json/
- https://tex-gaz.online/xmlrpc.php?rsd
- https://tex-gaz.online/wp-includes/wlwmanifest.xml
- https://tex-gaz.online/wp-json/oembed/1.0/embed?url=https%3A%2F%2Ftex-gaz.online%2F
- https://tex-gaz.online/wp-json/oembed/1.0/embed?url=https%3A%2F%2Ftex-gaz.online%2F&
- https://tex-gaz.online/wp-admin/admin-ajax.php
- https://tex-gaz.online/wp-content/plugins/js_composer/assets/css/vc_lte_ie9.min.css
- https://mc.yandex.ru/metrika/tag.js
- https://mc.yandex.ru/watch/64336822
- https://www.googletagmanager.com/gtag/js?id=UA-158851736-1
- https://mc.yandex.ru/watch/73526962
- https://tex-gaz.online
Embedded domains
- texgazz.ru
- tex-gaz.online
- ajax.googleapis.com
- schema.org
- api.w.org
- mc.yandex.ru
- www.googletagmanager.com
- www.w3.org
- zakis-azota.biz
- cdn.callibri.ru
- code.jivosite.com
- drop.dontstopthismusics.com
Embedded IP addresses
- 0.9.98.15
- 5.4.8.3
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report