MALICIOUS — 58cc9ae6b1445c7373a77190607a3a006887ea3a1c1123c8e1ebe49dd9dd1149
MALICIOUS — 58cc9ae6b1445c7373a77190607a3a006887ea3a1c1123c8e1ebe49dd9dd1149 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
58cc9ae6b1445c7373a77190607a3a006887ea3a1c1123c8e1ebe49dd9dd1149 - SHA-1:
dd16780c7fd01ea1359fe6d32dc8f2a91cd6d6ac - MD5:
db4f49f700f39d0f55909f02bdffdf8b - ssdeep:
1536:c/fmudaPte3bF4BmBq4P9YvmjbjRPRdKQ0pkv2:c/OudaPc3bmBmBN9YveBPKQ6T - TLSH:
T10D3AC6C0D2819EAB8E55AB11DDC720DD937BE3A3D112E46C4394FDD10939CAABC89439 - Submitted as: 58cc9ae6b1445c7373a77190607a3a006887ea3a1c1123c8e1ebe49dd9dd1149
- File type: html · Size: 93834 bytes
- Verdict: malicious (93/100)
Detections (2 of 53 engines)
- ClamAV (daily): Win.Trojan.Agent-36265
- Microsoft Defender: Trojan:Script/Wacatac.B!ml
Why this verdict
The malicious score of 93/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Agent-36265 (rule
Win.Trojan.Agent-36265) - engine signal, weight 0.90, confidence 0.95 - Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://i.imgur.com/0OOWbr2.png, https://cdn.statically.io/gh/Mo-AlCaesar/alcaesar-connect/0f09dff0/Caesar.js, https://cdn.statically.io/gh/Mo-AlCaesar/alcaesar-connect/ef9405c1/Caesar.css - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://i.imgur.com/0OOWbr2.png
- https://cdn.statically.io/gh/Mo-AlCaesar/alcaesar-connect/0f09dff0/Caesar.js
- https://cdn.statically.io/gh/Mo-AlCaesar/alcaesar-connect/ef9405c1/Caesar.css
- https://fonts.googleapis.com/css?family=Lato
- https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/css/font-awesome.min.css
- https://fonts.googleapis.com
- https://fonts.gstatic.com
- https://fonts.googleapis.com/css2?family=Changa&display=swap
- https://i.imgur.com/wjNOYF2.png
- https://i.imgur.com/fCIEbTa.png
- https://i.imgur.com/o6uUla7.png
- https://i.imgur.com/xiwqU6p.png
- https://i.imgur.com/pkHasE5.png
- https://i.imgur.com/DVypOt0.png
- https://i.imgur.com/iTVB9Xc.png
- https://i.imgur.com/v4mtdtZ.png
- https://i.imgur.com/HcKOv1l.png
- https://i.imgur.com/KffMijW.png
- https://www.ahlamontada.com
Embedded domains
- i.imgur.com
- cdn.statically.io
- fonts.googleapis.com
- cdnjs.cloudflare.com
- fonts.gstatic.com
- www.ahlamontada.com
- ahlamontada.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report