MALICIOUS — 5ed36188d6b89570351c773a7c751dbb4980ed779196423029cc18eaef28a661
MALICIOUS — 5ed36188d6b89570351c773a7c751dbb4980ed779196423029cc18eaef28a661 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the TrojanClicker family. 2 of 54 detection engines flagged it.
Identification
- SHA-256:
5ed36188d6b89570351c773a7c751dbb4980ed779196423029cc18eaef28a661 - SHA-1:
6335c065a7a156e16cd526c544897a781ded5922 - MD5:
8753aea447057199e334575ad36d98c6 - ssdeep:
1536:gdKsqkybmJvETP11Tj92DulfVndNEeNEX9tcOl7ZL:gPymJvEJ1TZ265VnwoOl7ZL - TLSH:
T1DF39C81A37467B4514D08817A6AC9FF0D1C1C22BFA3681EEE2F7BB94C838D70585A917 - Submitted as: 5ed36188d6b89570351c773a7c751dbb4980ed779196423029cc18eaef28a661
- File type: html · Size: 88358 bytes
- Verdict: malicious (92/100) · Family: TrojanClicker
Detections (2 of 54 engines)
- Microsoft Defender: TrojanClicker:JS/Faceliker.M
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 92/100 is the fusion of 7 weighted signals:
- Microsoft Defender flagged TrojanClicker:JS/Faceliker.M (rule
TrojanClicker:JS/Faceliker.M) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 1 external host(s) and 16 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css, http://pemulungnews.blogspot.com/favicon.ico, http://pemulungnews.blogspot.com/feeds/posts/default - static signal, weight 0.35, confidence 0.60
- Extracted generic config (14 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
279 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- desktop-hsgcbep
- login.live.com
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- licensing.mp.microsoft.com
Embedded URLs
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css
- http://pemulungnews.blogspot.com/favicon.ico
- http://pemulungnews.blogspot.com/2013/02/8-perubahan-gaya-hidup-untuk-kontrol.html
- http://pemulungnews.blogspot.com/feeds/posts/default
- http://pemulungnews.blogspot.com/feeds/posts/default?alt=rss
- https://www.blogger.com/feeds/4216839899780463103/posts/default
- http://pemulungnews.blogspot.com/feeds/6977036107020063426/comments/default
- http://3.bp.blogspot.com/-6WGcObWeRqs/USpIfxY8L1I/AAAAAAAAGt8/qtS-CRK3jrs/s640/8-perubahan-gaya-hidup-untuk-kontrol-diabetes.jpg
- http://3.bp.blogspot.com/-6WGcObWeRqs/USpIfxY8L1I/AAAAAAAAGt8/qtS-CRK3jrs/w1200-h630-p-k-no-nu/8-perubahan-gaya-hidup-untuk-kontrol-diabetes.jpg
- https://plus.google.com/108513714148154406937
- http://fonts.googleapis.com/css?family=Bitter%7CBitter%7CDroid+Sans%7CDroid+Sans%7CPT+Sans+Narrow
- http://ajax.googleapis.com/ajax/libs/jquery/1.7.1/jquery.min.js
- http://4.bp.blogspot.com/-xle7tRvibpc/UIecojbG6kI/AAAAAAAACw0/lvzIR05C3tI/s1600/socialicons.png
- http://2.bp.blogspot.com/-tVi3cEvCLXU/UMse6ueCWCI/AAAAAAAAHEc/Vsf2gOyYtE0/s1600/boxs-view.png
- http://4.bp.blogspot.com/-mGfhY72WR7g/UMse7tOeMkI/AAAAAAAAHEg/3kVZ9NFXJD4/s1600/multiple-view.png
- http://1.bp.blogspot.com/-Nmbn-wHI1Fc/UMylDHXHvYI/AAAAAAAAHHU/ywapTt6W6Io/s13/downarow.png
- http://1.bp.blogspot.com/-BeWBn44-iUQ/UMwY8JtxXjI/AAAAAAAAHFc/g9HZJch3tTU/s1600/15.png
- http://1.bp.blogspot.com/-_FihDWpLTR0/UMwY9YxrMJI/AAAAAAAAHFg/AgfjZCG-3Fo/s1600/16.png
- http://3.bp.blogspot.com/-GnsWJY-Hblo/UIbck16A3BI/AAAAAAAAGJM/qdog-XGwwQE/h20/sprite+images.png
- http://4.bp.blogspot.com/-r8YeL5MClP8/UIT2mjkPR6I/AAAAAAAAGGM/QM_4AcjZNfY/s1600/small-left.png
- http://1.bp.blogspot.com/-SovF-2Yqzx8/UIT2nmYLCuI/AAAAAAAAGGU/FjDXOtx5erk/s1600/small-right.png
- https://ajax.googleapis.com/ajax/libs/jquery/1.8.3/jquery.min.js
- http://ajax.googleapis.com/ajax/libs/jqueryui/1.8.23/jquery-ui.min.js
- http://2.bp.blogspot.com/-lQW7QlMoz10/T8yL_5IPF6I/AAAAAAAAAQU/5R8ngq17xzw/s1600/transparent.png
- https://lh5.googleusercontent.com/-X3QdKDj3k58/T6eaZd5gC7I/AAAAAAAACzc/fDy4RtkiWdQ/s0/noimage.jpg
Embedded domains
- www.blogger.com
- pemulungnews.blogspot.com
- 3.bp.blogspot.com
- plus.google.com
- fonts.googleapis.com
- ajax.googleapis.com
- fonts.gstatic.com
- 4.bp.blogspot.com
- 2.bp.blogspot.com
- 1.bp.blogspot.com
- risalahatiku46.blogspot.com
- google-analytics.com
- lh5.googleusercontent.com
- dedicahmad.googlecode.com
- blogspot.com
- data-vocabulary.org
- feeds.feedburner.com
- www.facebook.com
- img2.blogblog.com
- twitter.com
- www.stumbleupon.com
- digg.com
- delicious.com
- del.icio.us
- www.linkedin.com
Embedded IP addresses
- 20.42.73.30
- 52.123.252.227
- 4.230.171.124
- 57.155.101.212
- 4.144.132.114
- 74.178.76.128
- 20.165.94.54
- 4.150.223.104
- 4.150.223.98
- 172.64.154.167
- 20.184.175.21
- 20.42.73.27
- 52.110.12.50
- 125.56.205.24
- 125.56.205.51
- 72.153.5.96
- 52.148.114.188
- 52.110.12.55
- 52.110.12.20
More TrojanClicker samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report