MALICIOUS — 6ab308ac3b4b76697cf1b5d44a1e3eda9e23ee5dd44d7d7e069e9ba18d0c106b
MALICIOUS — 6ab308ac3b4b76697cf1b5d44a1e3eda9e23ee5dd44d7d7e069e9ba18d0c106b is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (74/100). 0 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6ab308ac3b4b76697cf1b5d44a1e3eda9e23ee5dd44d7d7e069e9ba18d0c106b - SHA-1:
70440ec1cbb28aba0dfc79474baef5a28eedda4e - MD5:
c2266ab7eee169d3d544c3fd5d6d6a08 - ssdeep:
768:lY6BWQf1OMr6OpeLEmGniHVyLtJQDuPBc6aOu0PEpwSSr/Ua43Mm:NBWQfYurpIEmGniHVyEu7EpwSSr/Ua4z - TLSH:
T1AA320A25E3572ED1C9AD1051F7E502D8C08F941B94342AEE8906EF86DC28F64BC5CEDA - Submitted as: 6ab308ac3b4b76697cf1b5d44a1e3eda9e23ee5dd44d7d7e069e9ba18d0c106b
- File type: html · Size: 46464 bytes
- Verdict: malicious (74/100)
Detections (0 of 54 engines)
No engine flagged this sample.
MITRE ATT&CK
Why this verdict
The malicious score of 74/100 is the fusion of 6 weighted signals:
- Obfuscated javascript script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 25 external host(s) and 12 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://ogp.me/ns#, https://get.belonnanotservice.ga/away?n1=t&, https://www.googletagmanager.com/gtag/js?id=UA-194170061-1 - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
17127 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 252.0.0.224.in-addr.arpa.
- tas02.sls.update.microsoft.com
- 164.142.190.20.in-addr.arpa.
- v10.events.data.microsoft.com
- settings-win.data.microsoft.com
- 175.117.168.52.in-addr.arpa.
- 204.77.179.74.in-addr.arpa.
- 40.85.84.40.in-addr.arpa.
- _ldap._tcp.dc._msdcs.WORKGROUP
Embedded URLs
- https://ogp.me/ns#
- https://get.belonnanotservice.ga/away?n1=t&
- https://katmoviehd.cf/wp-content/uploads/2021/04/cropped-KatMovie-G-S1.png
- https://www.googletagmanager.com/gtag/js?id=UA-194170061-1
- https://api.w.org/
- https://get.belonnanotservice.ga/away?n1=t&/wp-includes/wlwmanifest.xml
- https://cdnjs.cloudflare.com
- https://katmoviehd.sx/wp-content/uploads/2019/11/f2.jpg
- https://yellowpencil.waspthemes.com/
- http://3.bp.blogspot.com/-g-zH25_DoxI/VD1BuatkgII/AAAAAAAAAgc/00hxspfvv3s/s1600/searchbar.png
- http://4.bp.blogspot.com/-OcDQ6Z9ojlQ/VD1KnwJjFOI/AAAAAAAAAgs/cu_pKN6bpL8/s1600/magnifier.png
- https://1.bp.blogspot.com/-E7wgJa-BbIc/YFBDIjAkN_I/AAAAAAAAPco/4xU_UsOEbWAXuG0W149KujwC6hoQQwM4gCNcBGAsYHQ/s0/magnifier-hover.png
- https://cdn.ampproject.org/v0/amp-sidebar-0.1.js
- https://filmylinkers.in/tag/480p/
- https://filmylinkers.in/tag/720p/
- https://filmylinkers.in/tag/1080p/
- https://filmylinkers.in/tag/english/
- https://filmylinkers.in/tag/hindi/
- https://filmylinkers.in/tag/dual/
- https://katmoviehd.sx/wp-content/uploads/2018/11/Scott-Pilgrim-vs.-the-World-2010-Hindi-Dual-Auido-Free-Download.jpg
- https://catimage.net/images/2021/06/25/RAY-Season-1-2021-Netflix.jpg
- https://catimage.net/images/2021/06/16/The.Conjuring.3.2021-Sub.jpg
- https://catimage.net/images/2021/06/16/The.Conjuring.3.2021-Dub.jpg
- https://catimage.net/images/2021/05/28/Lucifer-2021-Season-5-Part-2-HINDI.jpg
- https://katmoviehd.sx/wp-content/uploads/2020/08/Lucifer-season-5-Hindi-Dubbed.jpg
Embedded domains
- ogp.me
- get.belonnanotservice.ga
- katmoviehd.cf
- schema.org
- secure.gravatar.com
- ajax.googleapis.com
- www.googletagmanager.com
- fonts.googleapis.com
- s.w.org
- api.w.org
- cdnjs.cloudflare.com
- yellowpencil.waspthemes.com
- 3.bp.blogspot.com
- 4.bp.blogspot.com
- 1.bp.blogspot.com
- cdn.ampproject.org
- filmylinkers.in
- catimage.net
- poetra.in
- katmoviehd.sx
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- _ldap._tcp.dc._msdcs.workgroup
Embedded IP addresses
- 2.1.4.1
- 172.215.188.232
- 20.42.179.204
- 57.154.63.210
- 20.42.65.85
- 40.84.85.40
- 52.168.117.175
- 51.116.246.105
- 203.26.79.13
- 57.155.104.224
- 20.42.73.26
- 52.168.117.174
- 72.145.35.96
- 48.211.4.16
- 4.247.188.224
- 4.247.188.233
- 52.123.129.14
- 92.223.78.30
- 85.210.196.11
- 74.179.77.204
- 40.84.97.4
- 172.172.255.218
- 135.233.95.80
- 52.148.114.188
- 20.42.179.192
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report