SUSPICIOUS — 78836e06e64fb9fd787a16bc263f0d2460531a53adc4720e493ff23c423bbcdf
SUSPICIOUS — 78836e06e64fb9fd787a16bc263f0d2460531a53adc4720e493ff23c423bbcdf is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
78836e06e64fb9fd787a16bc263f0d2460531a53adc4720e493ff23c423bbcdf - SHA-1:
368f46c40a9a57a038e09afac5e1ec2b0a3399a5 - MD5:
da0a2d477a6935afda0932e9a5275901 - ssdeep:
768:8PMo3vg2GOBq2Uz1xc/QTpsiOAYBOAcm/YREQQuuhwuNfeK:8PMevg2GOBKc/iOAYBOANOEbuuHP - TLSH:
T1C0368250B10AFE94C5C86AF2F06424F6D246D25F682509D1453CC78CACFCE74A86DEEA - Submitted as: 78836e06e64fb9fd787a16bc263f0d2460531a53adc4720e493ff23c423bbcdf
- File type: html · Size: 63548 bytes
- Verdict: suspicious (54/100)
Detections (2 of 53 engines)
- Microsoft Defender: Trojan:HTML/Beluga.SND!MTB
- Kaspersky (KVRT): HEUR:Trojan.JS.Miner.gen
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://royalscarservice.com/wp-content/cache/autoptimize/css/autoptimize_a8ad15415e31eb1772d8816d40664a70.css, https://royalscarservice.com/wp-content/cache/autoptimize/css/autoptimize_dcb2de333eec7ab4ae31385ed8d6a393.css, https://ajax.googleapis.com - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://royalscarservice.com/wp-content/cache/autoptimize/css/autoptimize_a8ad15415e31eb1772d8816d40664a70.css
- https://royalscarservice.com/wp-content/cache/autoptimize/css/autoptimize_dcb2de333eec7ab4ae31385ed8d6a393.css
- https://fonts.gstatic.com
- https://ajax.googleapis.com
- https://fonts.googleapis.com
- https://royalscarservice.com/feed/
- https://royalscarservice.com/comments/feed/
- https://royalscarservice.com/wp-content/cache/autoptimize/css/autoptimize_single_864d5ef16dfabcfa04d5471e38c8d860.css?ver=1622966134
- https://royalscarservice.com/wp-content/cache/autoptimize/css/autoptimize_single_7cefc5e68b751878122d572fb1ebe665.css?ver=1622966134
- https://royalscarservice.com/wp-content/cache/autoptimize/css/autoptimize_single_95aed3b51414047dab882e4d6792d0c2.css?ver=1622966134
- https://use.fontawesome.com/releases/v5.15.4/css/all.css?ver=2.0.1
- https://use.fontawesome.com/releases/v5.15.4/css/v4-shims.css?ver=2.0.1
- https://royalscarservice.com/wp-includes/js/jquery/jquery.js?ver=1.12.4-wp
- https://royalscarservice.com/wp-content/themes/rentit/js/iesupport/html5shiv.js?ver=5.3.2
- https://royalscarservice.com/wp-content/themes/rentit/js/iesupport/respond.min.js?ver=5.3.2
- https://api.w.org/
- https://royalscarservice.com/wp-json/
- https://royalscarservice.com/xmlrpc.php?rsd
- https://royalscarservice.com/wp-includes/wlwmanifest.xml
- https://royalscarservice.com/
- https://royalscarservice.com/wp-json/oembed/1.0/embed?url=https%3A%2F%2Froyalscarservice.com%2F
- https://royalscarservice.com/wp-json/oembed/1.0/embed?url=https%3A%2F%2Froyalscarservice.com%2F&
- https://royalscarservice.com/wp-content/plugins/js_composer/assets/css/vc_lte_ie9.min.css
- https://royalscarservice.com/wp-content/uploads/2018/03/cropped-Logo_royal-group_favicon-1-32x32.jpg
- https://royalscarservice.com/wp-content/uploads/2018/03/cropped-Logo_royal-group_favicon-1-192x192.jpg
Embedded domains
- royalscarservice.com
- maps.googleapis.com
- use.fontawesome.com
- s.w.org
- fonts.gstatic.com
- ajax.googleapis.com
- fonts.googleapis.com
- api.w.org
- schema.org
- secure.gravatar.com
- www.googletagmanager.com
- www.w3.org
- www.facebook.com
- twitter.com
- www.instagram.com
- www.youtube.com
- www.pinterest.com
- youtu.be
- www.google.com
- www.hostingcloud.racing
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report