MALICIOUS — 5bc72043084f7baf95528ae4fa891e25ca673d8cd5203042d7ac8202bd6c26c6
MALICIOUS — 5bc72043084f7baf95528ae4fa891e25ca673d8cd5203042d7ac8202bd6c26c6 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the Redirector family. 2 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5bc72043084f7baf95528ae4fa891e25ca673d8cd5203042d7ac8202bd6c26c6 - SHA-1:
c7d9021568b0e8479404218edd4bf8afc9d3a8c7 - MD5:
dcaa6140033273c01623e07193e166b2 - ssdeep:
3072:ke4z1+9Lqz7Np1C+4/aAXt82ilC0+NoVRzDzoBn2hWBibuWP+QTRR:kFk9LUp1C+4/aAXt8p/VVzo85 - TLSH:
T1FA3D093B72446B9F849564227E6C73E420CB85DFD82805E9F5D8DA88DC2DD701898CBB - Submitted as: 5bc72043084f7baf95528ae4fa891e25ca673d8cd5203042d7ac8202bd6c26c6
- File type: html · Size: 129104 bytes
- Verdict: malicious (92/100) · Family: Redirector
Detections (2 of 54 engines)
- Microsoft Defender: Trojan:HTML/Redirector.FL!bit
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 92/100 is the fusion of 8 weighted signals:
- Microsoft Defender flagged Trojan:HTML/Redirector.FL!bit (rule
Trojan:HTML/Redirector.FL!bit) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec, defense-evasion (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 24 external host(s) and 15 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/2326567743-css_bundle_v2_rtl.css, http://www.blogger.com/openid-server.g, http://health-healng.blogspot.com/ - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (12 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
13963 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 252.0.0.224.in-addr.arpa.
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 85.65.42.20.in-addr.arpa.
- tas02.sls.update.microsoft.com
- v10.events.data.microsoft.com
- ctldl.windowsupdate.com
- 30.78.223.92.in-addr.arpa.
- 64.167.190.20.in-addr.arpa.
- settings-win.data.microsoft.com
- 18.167.190.20.in-addr.arpa.
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.google.com/2005/gml/b
- http://www.google.com/2005/gml/data
- http://www.google.com/2005/gml/expr
- https://www.blogger.com/static/v1/widgets/2326567743-css_bundle_v2_rtl.css
- http://www.blogger.com/openid-server.g
- http://health-healng.blogspot.com/
- http://health-healng.blogspot.com/2014/11/blog-post_16.html
- http://health-healng.blogspot.com/feeds/posts/default
- http://health-healng.blogspot.com/feeds/posts/default?alt=rss
- http://www.blogger.com/feeds/410262918417019324/posts/default
- http://2.bp.blogspot.com/-q9qL9FH9GG4/VGjZpajihoI/AAAAAAAAKB8/azGr4ZWXmAc/s72-c/photo2_photomath.jpg
- https://plus.google.com/u/0/113628423801633150963
- https://www.blogger.com/static/v1/widgets/1535467126-widget_css_2_bundle.css
- http://fonts.googleapis.com/earlyaccess/droidarabickufi.css
- http://arlinadesign.blogspot.com
- http://mudwnp.blogspot.com
- http://creativecommons.org/licenses/by/3.0/
- http://themes.googleusercontent.com/static/fonts/opensans/v8/cJZKeOuBrn4kERxqtaUH3T8E0i7KZn-EPnyo3HZu7kw.woff
- http://fonts.gstatic.com/s/robotoslab/v6/y7lebkjgREBJK96VQi37ZuL2WfuF7Qc3ANwCvwl0TnA.woff2
- http://fonts.gstatic.com/s/oswald/v9/pEobIV_lL25TKBpqVI_a2w.woff2
- http://1.bp.blogspot.com/-SL82Yj_MkdE/VCNlr5Q1nWI/AAAAAAAAGf8/xzhe3TPouok/s1600/anonim.png
- http://4.bp.blogspot.com/-jSUS8v5kwpQ/U8Z_6Ufr-PI/AAAAAAAAEYY/o4cQPKvt8vQ/s1600/loading.gif
- http://1.bp.blogspot.com/-htG7vy9vIAA/Tp0KrMUdoWI/AAAAAAAABAU/e7XkFtErqsU/s1600/grey.GIF
- https://ajax.googleapis.com/ajax/libs/jquery/1.10.2/jquery.min.js
Embedded domains
- www.w3.org
- www.google.com
- www.blogger.com
- health-healng.blogspot.com
- 2.bp.blogspot.com
- plus.google.com
- netdna.bootstrapcdn.com
- fonts.googleapis.com
- arlinadesign.blogspot.com
- mudwnp.blogspot.com
- creativecommons.org
- themes.googleusercontent.com
- fonts.gstatic.com
- a.ai
- 1.bp.blogspot.com
- 4.bp.blogspot.com
- g.link
- ajax.googleapis.com
- blogspot.com
- connect.facebook.net
- www.facebook.com
- pagead2.googlesyndication.com
- entradas.link
- data-vocabulary.org
- img2.blogblog.com
Embedded IP addresses
- 172.172.255.217
- 4.247.188.224
- 40.84.97.4
- 40.84.85.40
- 20.42.73.31
- 20.42.65.88
- 74.178.76.44
- 203.26.79.13
- 20.42.65.85
- 74.178.76.128
- 51.11.192.48
- 92.223.78.30
- 72.153.5.129
- 52.123.252.233
- 4.150.223.115
- 85.210.196.11
- 172.215.188.225
- 4.150.223.98
- 52.123.128.14
- 20.42.179.204
- 20.50.201.203
- 20.42.73.28
- 52.148.114.188
- 85.210.193.152
- 52.168.117.170
More Redirector samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report