MALICIOUS — 74bac20c16c5f5ee549058f966dee8fd5de0e9e869d64b9bef785ce31db0e149
MALICIOUS — 74bac20c16c5f5ee549058f966dee8fd5de0e9e869d64b9bef785ce31db0e149 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 1 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
74bac20c16c5f5ee549058f966dee8fd5de0e9e869d64b9bef785ce31db0e149 - SHA-1:
7b5c4ec72560ad235c371db527894b9f2c7989a7 - MD5:
660b9229ddad1e3747601dc056b31789 - ssdeep:
1536:BDIRIOITIwIgIiKZgNDfIwIGI5IVJ7SqIRIOITIwIgIiKZgNDfIwIGI5IVJ7S6tk:f1gb770/2/0q6OL - TLSH:
T1CA3841416AD64DA6E1D8121CD2B14780B5CDBC061411AFCF81A8DFABBB0F76294F849F - Submitted as: 74bac20c16c5f5ee549058f966dee8fd5de0e9e869d64b9bef785ce31db0e149
- File type: html · Size: 82173 bytes
- Verdict: malicious (75/100)
Detections (1 of 54 engines)
- Microsoft Defender: Trojan:HTML/Phish.AC!MTB
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 3 weighted signals:
- Microsoft Defender flagged Trojan:HTML/Phish.AC!MTB (rule
Trojan:HTML/Phish.AC!MTB) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec (layers: char-code+concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://ogp.me/ns/fb#, https://payload.cargocollective.com/1/5/184126/6802280/CONKLIN_SL%20with%20Cupid_1.jpg, https://a.1stdibscdn.com/archivesE/upload/a_5543/1488210385499/ACK3seatedathletefacingright2_l.jpg - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
4895 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- 1.0.240.10.in-addr.arpa.
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 252.0.0.224.in-addr.arpa.
- 209.52.40.23.in-addr.arpa.
- dns.msftncsi.com
- 250.255.255.239.in-addr.arpa
- desktop-hsgcbep
- update.googleapis.com
- self.events.data.microsoft.com
- 251.0.0.224.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 142.195.250.142.in-addr.arpa
- 1.0.240.10.in-addr.arpa
Embedded URLs
- http://ogp.me/ns/fb#
- https://payload.cargocollective.com/1/5/184126/6802280/CONKLIN_SL%20with%20Cupid_1.jpg
- https://a.1stdibscdn.com/archivesE/upload/a_5543/1488210385499/ACK3seatedathletefacingright2_l.jpg
- https://bestnfile130.weebly.com/
- https://ajax.googleapis.com/ajax/libs/jquery/1.8.3/jquery.min.js
- https://www.google.com/recaptcha/api.js
- https://bestnfile130.weebly.com/1/post/2020/10/microsoft-works-database-update.html
- http://twitter.com/share?url=https://bestnfile130.weebly.com/1/post/2020/10/microsoft-works-database-update.html
- https://bestnfile130.weebly.com/1/post/2020/10/descargar-diccionario-biblia-vila-escuain-pdf-file.html
- http://twitter.com/share?url=https://bestnfile130.weebly.com/1/post/2020/10/descargar-diccionario-biblia-vila-escuain-pdf-file.html
- https://bestnfile130.weebly.com/1/post/2020/10/what-is-pdr-file.html
- http://twitter.com/share?url=https://bestnfile130.weebly.com/1/post/2020/10/what-is-pdr-file.html
- https://www.youtube.com/embed/XRWSE-VIB-I
- http://www.cargocollective.com/andrewsconklin
- https://bestnfile130.weebly.com/1/post/2020/10/andrew-s-conklin-painter.html
- http://twitter.com/share?url=https://bestnfile130.weebly.com/1/post/2020/10/andrew-s-conklin-painter.html
- https://bestnfile130.weebly.com/1/post/2020/10/beat-tags-for-free.html
- http://twitter.com/share?url=https://bestnfile130.weebly.com/1/post/2020/10/beat-tags-for-free.html
- https://bestnfile130.weebly.com/1/post/2020/10/pro-super-tuner-for-mac.html
- http://twitter.com/share?url=https://bestnfile130.weebly.com/1/post/2020/10/pro-super-tuner-for-mac.html
- https://www.weebly.com/signup?utm_source=internal&utm_medium=footer
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- ogp.me
- payload.cargocollective.com
- a.1stdibscdn.com
- bestnfile130.weebly.com
- cdn2.editmysite.com
- fonts.googleapis.com
- cdn1.editmysite.com
- ajax.googleapis.com
- www.weebly.com
- www.google.com
- twitter.com
- www.youtube.com
- gmail.com
- www.cargocollective.com
- google-analytics.com
- test.name
- ec.editmysite.com
- connect.facebook.net
- tter.com
Embedded IP addresses
- 135.234.160.245
- 20.42.65.94
- 72.154.7.99
- 4.150.223.103
- 4.247.188.233
- 20.184.175.0
- 4.150.223.110
- 51.105.71.136
- 72.145.35.109
- 52.148.114.188
- 72.145.35.97
- 203.26.79.13
- 72.145.35.96
- 172.172.255.216
- 172.172.255.218
- 40.84.97.4
- 4.150.223.109
- 4.150.223.112
- 52.123.252.204
- 52.168.117.168
- 104.208.16.94
- 85.210.193.152
- 20.247.184.142
- 52.110.12.49
- 52.110.12.31
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report