SUSPICIOUS — 6ad5b27bfc2c9c86699f4e2ea33ad96c2ff8cd5250cca69abd9af87df22734a5
SUSPICIOUS — 6ad5b27bfc2c9c86699f4e2ea33ad96c2ff8cd5250cca69abd9af87df22734a5 is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
6ad5b27bfc2c9c86699f4e2ea33ad96c2ff8cd5250cca69abd9af87df22734a5 - SHA-1:
d518367dd7a112fe59a9a94cfc88a759586ac5d5 - MD5:
4b402afa07e79e5adcd97f64c17ef4fc - ssdeep:
1536:I6oaZsyHY0FoNFT0crTnH1AW8/VbtkryKuJDbF/:bZq4oNFT0jbtGuJDbF/ - TLSH:
T11D34F91E3A497A4F04E0C5136D644AF4E0DB94E7953381F9E2A1FF84ED6CDA068498B3 - Submitted as: 6ad5b27bfc2c9c86699f4e2ea33ad96c2ff8cd5250cca69abd9af87df22734a5
- File type: html · Size: 56661 bytes
- Verdict: suspicious (54/100)
Detections (2 of 53 engines)
- Microsoft Defender: TrojanClicker:JS/Faceliker.N
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated powershell script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css, http://cvfanatic.blogspot.com/favicon.ico, http://cvfanatic.blogspot.com/search/label/Cityville%20tips - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.google.com/2005/gml/b
- http://www.google.com/2005/gml/data
- http://www.google.com/2005/gml/expr
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css
- http://cvfanatic.blogspot.com/favicon.ico
- http://cvfanatic.blogspot.com/search/label/Cityville%20tips
- http://cvfanatic.blogspot.com/feeds/posts/default
- http://cvfanatic.blogspot.com/feeds/posts/default?alt=rss
- https://www.blogger.com/feeds/4467544956822473438/posts/default
- http://www.bleuken.com/
- http://i178.photobucket.com/albums/w243/bleuken/bottom.gif
- http://i178.photobucket.com/albums/w243/bleuken/link_split.jpg
- http://i178.photobucket.com/albums/w243/bleuken/link_hover.jpg
- http://i178.photobucket.com/albums/w243/bleuken/arrow.gif
- https://www.blogger.com/dyn-css/authorization.css?targetBlogID=4467544956822473438&
- https://apis.google.com/js/plusone.js
- http://gi86.photobucket.com/groups/k115/F9377IFNNT/top.gif
- http://3.bp.blogspot.com/-1mR1ReCjMdg/Ta3zN8k4reI/AAAAAAAAAMk/Slm3KXtF_q4/s1600/87.png
- http://cvfanatic.blogspot.com/
- http://cvfanatic.blogspot.com/2011/12/new-link-cityville-free-15-xp.html
- http://cvfanatic.blogspot.com/search/label/CityVille%20Tipps
- http://cvfanatic.blogspot.com/2011/12/new-link-cityville-free-15-xp.html#comment-form
- http://static.ak.fbcdn.net/connect.php/js/FB.Share
- https://apps.facebook.com/cityville/incentivelink.php?sig=21b81204a294d04b10efd9ddae6b56b9&
Embedded domains
- www.w3.org
- www.google.com
- www.blogger.com
- cvfanatic.blogspot.com
- www.bleuken.com
- i178.photobucket.com
- blogspot.com
- apis.google.com
- pagead2.googlesyndication.com
- gi86.photobucket.com
- 3.bp.blogspot.com
- static.ak.fbcdn.net
- apps.facebook.com
- 2.bp.blogspot.com
- www.facebook.com
- 4.bp.blogspot.com
- i.imgur.com
- like.style.top
- yourjavascript.com
- claremontdesign.com
- www.blogblog.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report