MALICIOUS — 5bc254e4c096337c83b5f2ccbe1be9f25fe329f67717fb2c8236dbe7adc6047d
MALICIOUS — 5bc254e4c096337c83b5f2ccbe1be9f25fe329f67717fb2c8236dbe7adc6047d is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Obfus family. 2 of 54 detection engines flagged it.
Identification
- SHA-256:
5bc254e4c096337c83b5f2ccbe1be9f25fe329f67717fb2c8236dbe7adc6047d - SHA-1:
5ecf9e6937a4f3e70e746bf4d5ed7ab893f39474 - MD5:
016b80dc96066393416763759730ec93 - ssdeep:
768:euc6IqLV6N/v7hracZ+EeeeIeeDeteGn3VZxCISzXxqVyy:FBQ/v7hr5+EeeeIeeDeteGn3VZx/SzXM - TLSH:
T15C31964A17F765D2FCE104A6B51C8C884482FF079D35A2E98F65CF4D4A08BB2E46D4D2 - Submitted as: 5bc254e4c096337c83b5f2ccbe1be9f25fe329f67717fb2c8236dbe7adc6047d
- File type: html · Size: 40133 bytes
- Verdict: malicious (98/100) · Family: Obfus
Detections (2 of 54 engines)
- ClamAV (daily): Js.Trojan.Obfus-254
- Microsoft Defender: Trojan:HTML/Redirector.PGCF!MTB
Why this verdict
The malicious score of 98/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Js.Trojan.Obfus-254 (rule
Js.Trojan.Obfus-254) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:HTML/Redirector.PGCF!MTB (rule
Trojan:HTML/Redirector.PGCF!MTB) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 2 external host(s) and 6 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://onlineserver.at.ua/, http://g.ucoz.net/mochi/nano-recon/Nano%20Recon.swf, http://s40.radikal.ru/i089/0811/94/292f5884f6d6.gif - static signal, weight 0.35, confidence 0.60
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
277 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
- www.bing.com
- licensing.mp.microsoft.com
- th.bing.com
- fe3cr.delivery.mp.microsoft.com
Embedded URLs
- https://www.google.com/recaptcha/api.js?onload=reCallback&render=explicit&hl=ru
- http://onlineserver.at.ua/
- http://g.ucoz.net/mochi/nano-recon/Nano%20Recon.swf
- http://s40.radikal.ru/i089/0811/94/292f5884f6d6.gif
- http://s46.radikal.ru/i111/0811/0d/fc11979a3233.jpg
- http://i052.radikal.ru/0908/65/25fe4c8fb332.gif
- http://clanonlinecs.ucoz.ru/3.jpg
- http://clanonlinecs.ucoz.ru/6.jpg
- http://clanonlinecs.ucoz.ru/4.jpg
- http://top100.rambler.ru/home?id=2169994
- http://top100-images.rambler.ru/top100/banner-88x31-rambler-blue3.gif
- http://www.cys.ru/
- http://www.cys.ru/button.png?url=onlineserver.at.ua
- http://click.hotlog.ru/?2064007
- http://hit34.hotlog.ru/cgi-bin/hotlog/count
- http://hit34.hotlog.ru/cgi-bin/hotlog/count?s=2064007&im=101
- http://general-world.at.ua/rtr/1-2
- http://vkontakte.ru/id40140033
- http://fantasyflash.ru/vr2/vr16.htm
- http://informer.gismeteo.ru/html/js/showtlist_new.js
- http://informer.gismeteo.ru/html/js/ldata_new.js
- http://informer.gismeteo.ru/html/2.php?tnumber=7&city0=4368%D0%9C%D0%BE%D1%81%D0%BA%D0%B2%D0%B0&city1=5130%D0%90%D1%81%D1%82%D1%80%D0%B0%D1%85%D0%B0%D0%BD%D1%8C&city2=4787%D0%98%D1%80%D0%BA%D1%83%D1%82%D1%81%D0%BA&city3=4517%D0%95%D0%BA%D0%B0%D1%82%D0%B5%D1%80%D0%B8%D0%BD%D0%B1%D1%83%D1%80%D0%B3&city4=4051%D0%9B%D0%B0%D0%B2%D1%80%D0%B5%D0%BD%D1%82%D0%B8%D1%8F&city5=4862%D0%A5%D0%B0%D0%B1%D0%B0%D1%80%D0%BE%D0%B2%D1%81%D0%BA&city6=4565%D0%A7%D0%B5%D0%BB%D1%8F%D0%B1%D0%B8%D0%BD%D1%81%D0%BA&codepg=utf-8&par=4&inflang=rus&domain=ru&vieinf=1&p=1&w=1&tblstl=gmtbl&tdttlstl=gmtdttl&tdtext=gmtdtext&new_scheme=1
- http://img.yandex.net/i/money/top-5rub-aqua.gif
- https://money.yandex.ru/donate.xml
- http://img.yandex.net/i/money/bg-aqua.gif
Embedded domains
- counter.yadro.ru
- usite.pro
- my1.ru
- ucoz.net
- onlineserver.at.ua
- s33.ucoz.net
- www.google.com
- counter.rambler.ru
- g.ucoz.net
- s40.radikal.ru
- s46.radikal.ru
- i052.radikal.ru
- clanonlinecs.ucoz.ru
- top100.rambler.ru
- top100-images.rambler.ru
- www.cys.ru
- click.hotlog.ru
- hit34.hotlog.ru
- general-world.at.ua
- online.ua
- vkontakte.ru
- xaker.ru
- fantasyflash.ru
- informer.gismeteo.ru
- img.yandex.net
Embedded IP addresses
- 20.184.175.6
- 4.230.171.124
- 40.84.97.4
- 4.144.132.114
- 74.179.77.164
- 13.89.179.12
- 74.178.76.128
- 172.64.154.167
- 85.210.193.152
- 20.42.73.26
- 52.110.12.37
- 52.110.12.15
- 72.145.35.109
- 52.110.12.47
- 52.110.12.52
- 52.148.114.188
More Obfus samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report