SUSPICIOUS — virussign.com_5e5a1e91dea964a68a94b883777fc640.vir
SUSPICIOUS — virussign.com_5e5a1e91dea964a68a94b883777fc640.vir is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 1 of 50 detection engines flagged it.
Identification
- SHA-256:
7705de61253beb7948db64f1eb29fd5953f6d14d0bb1c2b11e02e9f48907b78d - SHA-1:
2c5099b86867be0c6cf05ea18ca618b829312160 - MD5:
5e5a1e91dea964a68a94b883777fc640 - ssdeep:
384:1+FaG/zoYbWh6XHhLRL3LLdLjuC2KMdllSLNxDgG:1+F98YbWhUH1F7Nh2KMqzDP - TLSH:
T1EC27F95FB3093E4F16E0000A6B8C5AECD48E65DF58239365CAE77D81EC39C247650ACA - Submitted as: virussign.com_5e5a1e91dea964a68a94b883777fc640.vir
- File type: html · Size: 15666 bytes
- Verdict: suspicious (54/100)
Source: VirusSign · first seen 2026-08-10T00:00:00.000Z · SHA-256 verified
Detections (1 of 50 engines)
- Microsoft Defender: Trojan:HTML/Phish.Q!AMTB
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/4165133002-widget_css_bundle.css, https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEilC2l3LrVCibOQONHCL-e9MSxTQhLhCr4U4GTqMRKPV1PI-e0hlvyNxY37eJtQHaWDNR62hl_0q3L-4Ju66etPYQfdBC9GhB6v_4IUGaicC4abXy5dlLZG7EDTbJ0rouhqQC-3r1agX6Cgp_X4ZiGmbw_jm4gku7rNN3Ynqtd9ZjECqqmqNKB3cB0LQg/s960/186540176_263056208933382_202676063141365368_n.jpg, https://www.googletagmanager.com/gtag/js?id=UA-106461302-1 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.google.com/2005/gml/b
- http://www.google.com/2005/gml/data
- http://www.google.com/2005/gml/expr
- https://www.blogger.com/static/v1/widgets/4165133002-widget_css_bundle.css
- https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEilC2l3LrVCibOQONHCL-e9MSxTQhLhCr4U4GTqMRKPV1PI-e0hlvyNxY37eJtQHaWDNR62hl_0q3L-4Ju66etPYQfdBC9GhB6v_4IUGaicC4abXy5dlLZG7EDTbJ0rouhqQC-3r1agX6Cgp_X4ZiGmbw_jm4gku7rNN3Ynqtd9ZjECqqmqNKB3cB0LQg/s960/186540176_263056208933382_202676063141365368_n.jpg
- https://www.googletagmanager.com/gtag/js?id=UA-106461302-1
- https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhx6uWmk91EllLwq1ExS8vNGBsXVEISKijcJRnyvJRJ5xocJf9DGQi-Ytfcs3FBBWTcTDKJDTj4RggM27BCh3sSr5xJCKokKWOe1jUjdbUsont0tPN73iZcW8P8G7AIaZxfjaYG3BjGypqUObvOPDoMBTKo1rGQipLnSHO_zI6WEyOKgIOGBBMCwzbv/s1877/498d75a28ac54a9b13d4.jpg
- https://www.blogger.com/static/v1/widgets/3432011497-widgets.js
- https://clip5437857834534.blogspot.com/
- https://clip5437857834534.blogspot.com/search
- https://clip5437857834534.blogspot.com/favicon.ico
- https://www.blogger.com
- https://apis.google.com/js/platform.js
- https://www.fk-austria.at/?proxy=images/waiting.gif
- https://maxcdn.bootstrapcdn.com/bootstrap/3.4.1/css/bootstrap.min.css
- https://ajax.googleapis.com/ajax/libs/jquery/3.5.1/jquery.min.js
- https://maxcdn.bootstrapcdn.com/bootstrap/3.4.1/js/bootstrap.min.js
- https://ipinfo.io/json
- https://is.gd/idX9d2
Embedded domains
- www.w3.org
- www.google.com
- www.blogger.com
- blogger.googleusercontent.com
- www.googletagmanager.com
- blogspot.com
- clip5437857834534.blogspot.com
- www.blogblog.com
- apis.google.com
- maxcdn.bootstrapcdn.com
- ajax.googleapis.com
- ipinfo.io
- tlscph.xyz
- www.fk-austria.at
- is.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report