MALICIOUS — 5edcccee284551570f567f9a25c213e4ae5e3a317b9c34f93e0be1a4d568dbde
MALICIOUS — 5edcccee284551570f567f9a25c213e4ae5e3a317b9c34f93e0be1a4d568dbde is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (84/100). 1 of 54 detection engines flagged it.
Identification
- SHA-256:
5edcccee284551570f567f9a25c213e4ae5e3a317b9c34f93e0be1a4d568dbde - SHA-1:
021b826b14cb21a33359b962de47fd723ae6b58d - MD5:
1f400b70b3f7126d8e1112315014fe69 - ssdeep:
6144:2bcKFtPykViMbxjzgmbzbI0bQJX0XZXlXYXTXbX2XLX6X+Xd8fQcdcN6Blsw1MKp:2bcKFtPykViMbxjzgmbzbI0bQY8fQcd1 - TLSH:
T17345E9FD73A6678F5D4177C3BBE92368997655C7E22294D1DC2727C18CA9C302C0A0A2 - Submitted as: 5edcccee284551570f567f9a25c213e4ae5e3a317b9c34f93e0be1a4d568dbde
- File type: html · Size: 290244 bytes
- Verdict: malicious (84/100)
Detections (1 of 54 engines)
- Microsoft Defender: Trojan:HTML/Scrinject.C!bit
Why this verdict
The malicious score of 84/100 is the fusion of 5 weighted signals:
- Microsoft Defender flagged Trojan:HTML/Scrinject.C!bit (rule
Trojan:HTML/Scrinject.C!bit) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 17 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css, http://bt.blog4temp.com, http://www.soratemplates.com - static signal, weight 0.35, confidence 0.60
- Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
288 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
Embedded URLs
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css
- http://bt.blog4temp.com
- http://www.soratemplates.com
- http://daneden.me/animate
- http://opensource.org/licenses/MIT
- https://github.com/nickpettit/glide
- http://landofcoder.com
- http://1.bp.blogspot.com/-QjSndGbF0No/T-Nt3HgKsDI/AAAAAAAAG9o/cN6_Oy306rc/s1600/no-video.gif
- https://www.blogger.com/dyn-css/authorization.css?targetBlogID=6496067696784934520&
- https://lh6.googleusercontent.com/proxy/4dhEuu45fEMTHL58UXF4iAEGuIo-YCq6tCUILCJdlA9-ejYImSrAegwm3OjFnKGHxS9VGhetN-qW2dhC41zsPielD5kr6bg8ZKLiHq7L0vsFrbN_Ulc=s0-d
- https://animeseasonshare.blogspot.com/
- http://babrkun.blogspot.com/search/label/%D8%AA%D8%A7%D8%B1%D9%8A%D8%AE%D9%8A
- http://babrkun.blogspot.com/search/label/%D9%85%D9%8A%D9%83%D8%A7
- http://babrkun.blogspot.com/search/label/%D8%AE%D9%8A%D8%A7%D9%84
- http://animeseasonshare.blogspot.com/search/label/%D8%A7%D9%83%D8%B4%D9%86
- http://babrkun.blogspot.com/search/label/%D8%AF%D8%B1%D8%A7%D9%85%D8%A7
- http://animeseasonshare.blogspot.com/search/label/%D8%B1%D8%B9%D8%A8
- http://babrkun.blogspot.com/search/label/%D8%B3%D9%81%D8%B1%20%D8%B9%D8%A8%D8%B1%20%D8%A7%D9%84%D8%B2%D9%85%D9%86
- https://animeseasonshare.blogspot.com/search/label/AnimeList
- https://animeseasonshare.blogspot.com/search/label/Blu-ray
- https://animeseasonshare.blogspot.com/search/label/mirai%20nikki
- https://animeseasonshare.blogspot.com/search/label/%D8%A8%D9%84%D9%88%D8%A7%D8%B1%D9%8A
- https://animeseasonshare.blogspot.com/2016/08/mirai-nikki.html
- https://animeseasonshare.blogspot.com/2016/08/mirai-nikki.html#comment-form
- https://1.bp.blogspot.com/-KdTGBB6x-XY/V7C8QfoB68I/AAAAAAAAARM/rI4L8I2CVSods-QieHFS6yO0k4Edc-KOACK4B/s320/280full.jpg
Embedded domains
- www.blogger.com
- fonts.googleapis.com
- maxcdn.bootstrapcdn.com
- bt.blog4temp.com
- www.soratemplates.com
- 4.bp.blogspot.com
- 2.bp.blogspot.com
- 1.bp.blogspot.com
- 3.bp.blogspot.com
- daneden.me
- opensource.org
- github.com
- ajax.googleapis.com
- yourjavascript.com
- gmail.com
- landofcoder.com
- entry.link
- blogspot.com
- lh6.googleusercontent.com
- animeseasonshare.blogspot.com
- babrkun.blogspot.com
- s7.addthis.com
- auth.name
- comment.link
- comment.author.name
Embedded IP addresses
- 20.89.1.10
- 52.123.252.219
- 4.230.171.124
- 48.211.4.16
- 20.247.185.124
- 74.179.77.204
- 74.178.76.54
- 20.42.65.90
- 20.165.94.63
- 172.64.154.167
- 4.150.223.109
- 57.154.63.210
- 92.223.78.30
- 72.153.5.134
- 52.148.114.188
- 52.110.12.14
- 52.110.12.24
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report