SUSPICIOUS — 80ed0814d7809247d46edb8eefd1b10ba91ab6ddb687778ac06465170238eed0
SUSPICIOUS — 80ed0814d7809247d46edb8eefd1b10ba91ab6ddb687778ac06465170238eed0 is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
80ed0814d7809247d46edb8eefd1b10ba91ab6ddb687778ac06465170238eed0 - SHA-1:
ff9f776ac083a877dcb9bb6b0695e63ac820c850 - MD5:
2cf4aa74240fd178c30bc51762b5f703 - ssdeep:
1536:8WkADkAZckABKQbZkAXhTcr0IPGNMxZPdJXxPTQakAW+SOvFSmLApvWb329RGpen:HkADkAikAIGZkARTcr0uGNMxZPdJXxPC - TLSH:
T16D360A1BB3217A4F8DB4611559BD62D420CB825BA93367E6C9DBEF858C2CC217C8C439 - Submitted as: 80ed0814d7809247d46edb8eefd1b10ba91ab6ddb687778ac06465170238eed0
- File type: html · Size: 67167 bytes
- Verdict: suspicious (54/100)
Detections (2 of 50 engines)
- Microsoft Defender: TrojanClicker:JS/Faceliker.M
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1667664774-css_bundle_v2.css, http://1.bp.blogspot.com/-miDISEVzUkc/UY-f1Bd_y0I/AAAAAAAAAo0/CskBfjOpJBw/s1600/favicon.ico, http://s.haivl.com/content/images/logo_smiley.jpg - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.google.com/2005/gml/b
- http://www.google.com/2005/gml/data
- http://www.google.com/2005/gml/expr
- https://www.blogger.com/static/v1/widgets/1667664774-css_bundle_v2.css
- http://1.bp.blogspot.com/-miDISEVzUkc/UY-f1Bd_y0I/AAAAAAAAAo0/CskBfjOpJBw/s1600/favicon.ico
- https://plus.google.com/u/0/101055844436873940439/about
- https://plus.google.com/u/0/101055844436873940439/posts
- http://s.haivl.com/content/images/logo_smiley.jpg
- http://s.haivl.com/content/images/logo_40.png
- http://s.haivl.com/content/images/upload_icon.png
- http://s.haivl.com/content/images/down_icon.png
- http://s.haivl.com/content/images/admin/icons/exclamation.png
- http://s.haivl.com/content/images/admin/icons/information.png
- http://s.haivl.com/content/images/admin/icons/tick_circle.png
- http://s.haivl.com/content/images/admin/icons/cross_circle.png
- http://s.haivl.com/content/images/admin/icons/cross_grey_small.png
- http://s.haivl.com/content/images/vote_icon.png
- http://s.haivl.com/content/images/view_icon.png
- http://s.haivl.com/content/images/comment_icon.png
- http://s.haivl.com/content/images/source_icon.png
- http://s.haivl.com/content/images/like_icon.png
- http://s.haivl.com/content/images/smile_icon.png
- http://s.haivl.com/content/images/prev_icon.png
- http://s.haivl.com/content/images/next_icon.png
Embedded domains
- www.w3.org
- www.google.com
- www.blogger.com
- 1.bp.blogspot.com
- djdownload.biz
- plus.google.com
- s.haivl.com
- nguyenhuytap.googlecode.com
- www.facebook.com
- blogspot.com
- apis.google.com
- xinhxau.blogspot.com
- pagead2.googlesyndication.com
- schema.org
- resources.blogblog.com
- b.name
- lamdepphunu.com
- kenh18.info
- proxy.link
- www.xvideos.com
- www.kenh18.info
- img100.xvideos.com
- www.hai24vn.com
- docs.google.com
- twitter.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report