MALICIOUS — 8859780c4575748898796b5c34cab9b63b98e0fa83b9230501e28102da84d86c
MALICIOUS — 8859780c4575748898796b5c34cab9b63b98e0fa83b9230501e28102da84d86c is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100), attributed to the Redirector family. 4 of 51 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8859780c4575748898796b5c34cab9b63b98e0fa83b9230501e28102da84d86c - SHA-1:
0e2412780c0277af727250214d6072a7fc0f80a6 - MD5:
72df8587f5581320d9eb1b534d0ae622 - ssdeep:
384:dpU3naplgIFsPMm5oU7PSgzQOeo1Xd2qOMn3GV:dpUKpi1P55oU76aeoq6m - TLSH:
T18B2980925B5731FD939C441B1230DE66AA60380ABC702A7E536803356DACEA3D5CF763 - Submitted as: 8859780c4575748898796b5c34cab9b63b98e0fa83b9230501e28102da84d86c
- File type: html · Size: 20091 bytes
- Verdict: malicious (93/100) · Family: Redirector
Detections (4 of 51 engines)
- Microsoft Defender: Trojan:JS/Redirector.ARR!MTB
- Emsisoft (Emergency Kit): JS:Trojan.Cryxos.2990
- Kaspersky (KVRT): Trojan-Downloader.HTML.JScript.dj
- Trellix Stinger (McAfee): JS/Exploit-Blacole.hv
MITRE ATT&CK
Why this verdict
The malicious score of 93/100 is the fusion of 7 weighted signals:
- Memory forensics: 4 finding(s), e.g. RWX/private injected region in taskhostw.exe (pid 6892) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:JS/Redirector.ARR!MTB (rule
Trojan:JS/Redirector.ARR!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged JS:Trojan.Cryxos.2990 (rule
JS:Trojan.Cryxos.2990) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: defense-evasion (rule
script-deobfuscation) - static signal, weight 0.35, confidence 0.75 - Embedded network infrastructure: http://gmpg.org/xfn/11, http://template.com/wp/?feed=rss2, http://template.com/wp/xmlrpc.php - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (15 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
275 behavior events · 1 ATT&CK techniques · 1 dropped files.
Runtime network
- searchapp.bundleassets.example
- www.msftconnecttest.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- tas02.sls.update.microsoft.com
- config.edge.skype.com
- www.bing.com
- ctldl.windowsupdate.com
- to-do.microsoft.com
- settings-win.data.microsoft.com
- dns.msftncsi.com
- staging.to-do.microsoft.com
- edge.microsoft.com
- watson.events.data.microsoft.com
- teams.microsoft.com
- aps.prod.windows.com
Dropped files
- ce225d64589e14f8ca17792329a6c75f6c1f0b006ae3a0a193ee780e49530be3 -
ce225d64589e14f8ca17792329a6c75f6c1f0b006ae3a0a193ee780e49530be3
Embedded URLs
- http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd
- http://www.w3.org/1999/xhtml
- http://gmpg.org/xfn/11
- http://template.com/wp/?feed=rss2
- http://template.com/wp/xmlrpc.php
- http://template.com/wp/xmlrpc.php?rsd
- http://template.com/wp/wp-includes/wlwmanifest.xml
- http://template.com/wp/
- https://besixoni.tripod.com/polio-encephalitis-goats/
- https://besixoni.tripod.com/replenishment-specialist/
- https://besixoni.tripod.com/babado-novo-pensando-em-vc/
- https://besixoni.tripod.com/alta-vista-college-seattle/
- https://besixoni.tripod.com/errin-tablets-dietary-supplements/
- https://besixoni.tripod.com/first-synthesis-of-methyl-salicylate/
- https://besixoni.tripod.com/clonazepam-addiction/
- https://besixoni.tripod.com/20-foot-1993-chaparral/
- https://besixoni.tripod.com/todsen-pennyroyal-white-sands/
Embedded domains
- www.w3.org
- gmpg.org
- template.com
- besixoni.tripod.com
- staging.to-do.officeppe.com
More Redirector samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report