MALICIOUS — 5bcafefd1c2b402b3ebe15e7bd1464fcc53f08a2991c6703eb1e0b6ae7d7e56e
MALICIOUS — 5bcafefd1c2b402b3ebe15e7bd1464fcc53f08a2991c6703eb1e0b6ae7d7e56e is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Autolike family. 3 of 54 detection engines flagged it.
Identification
- SHA-256:
5bcafefd1c2b402b3ebe15e7bd1464fcc53f08a2991c6703eb1e0b6ae7d7e56e - SHA-1:
960b3c68e20218994dd68932803b7d1ac8889b82 - MD5:
6f972228ed5ba0c82adb74b4355939e2 - ssdeep:
768:rpROQzeTVRP2BpBL0kTc8FeSeIFCUN2IrDUw75CVF5MXOkSWwR8b/o:dR36ApBzTc8FeSbFC82IsYC5MXOkSWwH - TLSH:
T1D32FC72769576DDF1CA050535C6D07D850CE87D7C833C2E4A962EF8CE878C246C698EA - Submitted as: 5bcafefd1c2b402b3ebe15e7bd1464fcc53f08a2991c6703eb1e0b6ae7d7e56e
- File type: html · Size: 35060 bytes
- Verdict: malicious (99/100) · Family: Autolike
Detections (3 of 54 engines)
- ClamAV (daily): Js.Malware.Autolike-1
- Microsoft Defender: TrojanClicker:JS/Faceliker.C
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 99/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Js.Malware.Autolike-1 (rule
Js.Malware.Autolike-1) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged TrojanClicker:JS/Faceliker.C (rule
TrojanClicker:JS/Faceliker.C) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 16 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css, http://statusuri1000.blogspot.com/favicon.ico, http://statusuri1000.blogspot.com/search/label/statusuri%20despre%20fete?updated-max=2013-08-19T01:47:00-07:00 - static signal, weight 0.35, confidence 0.60
- Extracted generic config (15 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
279 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.google.com/2005/gml/b
- http://www.google.com/2005/gml/data
- http://www.google.com/2005/gml/expr
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css
- http://statusuri1000.blogspot.com/favicon.ico
- http://statusuri1000.blogspot.com/search/label/statusuri%20despre%20fete?updated-max=2013-08-19T01:47:00-07:00
- http://statusuri1000.blogspot.com/feeds/posts/default
- http://statusuri1000.blogspot.com/feeds/posts/default?alt=rss
- https://www.blogger.com/feeds/4270318300047606943/posts/default
- http://www.templatemo.com/templates/templatemo_063_green_blog/images/templatemo_content_bg.jpg
- http://www.templatemo.com/templates/templatemo_063_green_blog/images/templatemo_menu_panel_bg.jpg
- http://www.templatemo.com/templates/templatemo_063_green_blog/images/templatemo_post_bg.jpg
- http://www.templatemo.com/templates/templatemo_063_green_blog/images/templatemo_right_section_bg.jpg
- http://www.templatemo.com/templates/templatemo_063_green_blog/images/templatemo_content_bottom.jpg
- http://www.templatemo.com/templates/templatemo_063_green_blog/images/templatemo_footer_bg.jpg
- http://code.jquery.com/jquery-1.4.2.min.js
- https://www.blogger.com/dyn-css/authorization.css?targetBlogID=4270318300047606943&
- https://pagead2.googlesyndication.com/pagead/js/adsbygoogle.js
- http://statusuri1000.blogspot.com/
- http://4.bp.blogspot.com/-QAYqDecxoxE/UrWJ7dhmUtI/AAAAAAAAAcw/segAH59TBuw/s1600/%D0%B7%D0%B0%D0%B3%D1%80%D1%83%D0%B6%D0%B5%D0%BD%D0%BD%D0%BE%D0%B5+
- https://4.bp.blogspot.com/-QAYqDecxoxE/UrWJ7dhmUtI/AAAAAAAAAcw/segAH59TBuw/s1600/%D0%B7%D0%B0%D0%B3%D1%80%D1%83%D0%B6%D0%B5%D0%BD%D0%BD%D0%BE%D0%B5+
- http://statusuri1000.blogspot.com/search/label/statusuri%20haioase
- http://4.bp.blogspot.com/-DWH22BmWkGU/UrWJ7pxlKDI/AAAAAAAAAc4/rVDjCzUFwj8/s1600/%D0%B7%D0%B0%D0%B3%D1%80%D1%83%D0%B6%D0%B5%D0%BD%D0%BD%D0%BE%D0%B5+
- https://4.bp.blogspot.com/-DWH22BmWkGU/UrWJ7pxlKDI/AAAAAAAAAc4/rVDjCzUFwj8/s1600/%D0%B7%D0%B0%D0%B3%D1%80%D1%83%D0%B6%D0%B5%D0%BD%D0%BD%D0%BE%D0%B5+
Embedded domains
- www.w3.org
- www.google.com
- www.blogger.com
- statusuri1000.blogspot.com
- www.bloggerthemes.net
- www.templatemo.com
- code.jquery.com
- blogspot.com
- pagead2.googlesyndication.com
- icontainer.style.top
- 4.bp.blogspot.com
- 2.bp.blogspot.com
- 3.bp.blogspot.com
- 1.bp.blogspot.com
- feedjit.com
- apis.google.com
- www.gstatic.com
- hosted.muses.org
- www.teestnet.com
- www.blogblog.com
- mp3.radiohot.ro
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 20.42.73.28
- 4.230.171.124
- 48.211.4.16
- 40.84.85.40
- 104.208.16.94
- 20.247.184.197
- 135.232.92.97
- 20.165.94.63
- 52.168.117.174
- 162.159.142.9
- 40.79.163.155
- 20.42.73.31
- 72.145.35.111
- 52.148.114.188
- 52.110.12.10
- 52.110.12.38
More Autolike samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report