SUSPICIOUS — 83c54e86a84362aa119631d04c4d5ab7c8d63a7ad1e7af64eda3cf4f5f053400
SUSPICIOUS — 83c54e86a84362aa119631d04c4d5ab7c8d63a7ad1e7af64eda3cf4f5f053400 is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
83c54e86a84362aa119631d04c4d5ab7c8d63a7ad1e7af64eda3cf4f5f053400 - SHA-1:
1a4f11709f060c9511487a259395658dabc27359 - MD5:
0e185ddc046b44436854d0b68c107813 - ssdeep:
192:oKSDS95CdjuVwLOtdjr8Bwlm+nIr1l3wqQo1CfGOCGpCPqq6jylq5ij:otWDCsqLOtVLm+nIr1lg9yOPpij - TLSH:
T1AA22081F53757DCF82A11E0A75BC72AD080779CA8E5010E5EDDFBD818C9AC36A88C166 - Submitted as: 83c54e86a84362aa119631d04c4d5ab7c8d63a7ad1e7af64eda3cf4f5f053400
- File type: html · Size: 10066 bytes
- Verdict: suspicious (54/100)
Detections (2 of 53 engines)
- Microsoft Defender: flagged
- Kaspersky (KVRT): HEUR:Hoax.HTML.Phish.gen
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://excel567.oss-ap-southeast-3.aliyuncs.com/pdf.js, https://cdn.glitch.com/a9bfcce0-422b-46e4-9074-3147cbc03390%2Ficon.ico?v=1600376585636, https://cdn.glitch.com/a9bfcce0-422b-46e4-9074-3147cbc03390%2Fbg.jpg?v=1600376573408 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://excel567.oss-ap-southeast-3.aliyuncs.com/pdf.js
- https://cdn.glitch.com/a9bfcce0-422b-46e4-9074-3147cbc03390%2Ficon.ico?v=1600376585636
- https://cdn.glitch.com/a9bfcce0-422b-46e4-9074-3147cbc03390%2Fbg.jpg?v=1600376573408
- https://code.jquery.com/jquery-3.2.1.slim.min.js
- https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/umd/popper.min.js
- https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/js/bootstrap.min.js
- https://ajax.googleapis.com/ajax/libs/jquery/2.2.4/jquery.min.js
- https://stackpath.bootstrapcdn.com/bootstrap/4.1.3/js/bootstrap.min.js
- https://drive.google.com/drive/u/0/my-drive
Embedded domains
- excel567.oss-ap-southeast-3.aliyuncs.com
- cdn.glitch.com
- bittium.com
- code.jquery.com
- cdnjs.cloudflare.com
- maxcdn.bootstrapcdn.com
- ajax.googleapis.com
- stackpath.bootstrapcdn.com
- drive.google.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report