MALICIOUS — 89c8bc15c6311b711126d8ee1a0cd3012596af0003d9522d16a4079f05b8df66
MALICIOUS — 89c8bc15c6311b711126d8ee1a0cd3012596af0003d9522d16a4079f05b8df66 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 1 of 54 detection engines flagged it.
Identification
- SHA-256:
89c8bc15c6311b711126d8ee1a0cd3012596af0003d9522d16a4079f05b8df66 - SHA-1:
41404cadb549e6245cd87c313b76f3ba7e4feb1a - MD5:
17038144e7ec4bafa9b1694c2949a549 - ssdeep:
768:ruApd8w4IBOEe95InGgQhUMAEmu89CuLVZ8QoPaUo6ilXzFi4o/W+xjfzIBke7PW:ruWGw4I5khqCOZyP47jFi4o/LzM+W3te - TLSH:
T18730C80E3249694F8DE0117179FAABD420CF9D0BF43249E2E8639F49D864C667D90CAD - Submitted as: 89c8bc15c6311b711126d8ee1a0cd3012596af0003d9522d16a4079f05b8df66
- File type: html · Size: 37059 bytes
- Verdict: malicious (96/100)
Detections (1 of 54 engines)
- ClamAV (daily): Win.Trojan.Crypt-291
Why this verdict
The malicious score of 96/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Crypt-291 (rule
Win.Trojan.Crypt-291) - engine signal, weight 0.90, confidence 0.95 - Obfuscated javascript script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 1 external host(s) and 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css, http://fstencilprueba.blogspot.com/favicon.ico, http://fstencilprueba.blogspot.com/ - static signal, weight 0.35, confidence 0.60
- Extracted generic config (16 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
279 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- windows.msn.com
- www.msn.com
- licensing.mp.microsoft.com
- assets.msn.com
- www.bing.com
- edge.microsoft.com
- time.windows.com
- settings-win.data.microsoft.com
- geo.prod.do.dsp.mp.microsoft.com
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.google.com/2005/gml/b
- http://www.google.com/2005/gml/data
- http://www.google.com/2005/gml/expr
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css
- http://fstencilprueba.blogspot.com/favicon.ico
- http://fstencilprueba.blogspot.com/
- http://fstencilprueba.blogspot.com/feeds/posts/default
- http://fstencilprueba.blogspot.com/feeds/posts/default?alt=rss
- https://www.blogger.com/feeds/3308349593484757740/posts/default
- https://www.blogger.com/profile/01814611193202891029
- http://falconhive.com/2009/05/milano-blogger-template/
- http://falconhive.com
- http://1.bp.blogspot.com/_hcF8ssiWKd4/ShebyqPZsPI/AAAAAAAAA_Q/tx-O9hfu-Ek/s1600/casing.jpg
- http://2.bp.blogspot.com/_hcF8ssiWKd4/ShebzdfPCvI/AAAAAAAAA_w/GHFbD2BjatA/s1600/logo.png
- http://2.bp.blogspot.com/_hcF8ssiWKd4/Sheb0U0PqII/AAAAAAAABAY/2_zWiBlbFXA/s1600/search.png
- http://3.bp.blogspot.com/_hcF8ssiWKd4/Sheb0VOQXxI/AAAAAAAABAg/ROgFoh77hIM/s1600/sform.png
- http://3.bp.blogspot.com/_hcF8ssiWKd4/Sheb0IkVTmI/AAAAAAAABAQ/Sx0pLf4ZHvE/s1600/sbutton.png
- http://1.bp.blogspot.com/_hcF8ssiWKd4/ShebyyxYU-I/AAAAAAAAA_Y/AkqfH37LCrk/s1600/catmen.jpg
- http://3.bp.blogspot.com/_hcF8ssiWKd4/ShebzCC96gI/AAAAAAAAA_g/DCD6yTPzHhk/s1600/catmenhov.jpg
- http://3.bp.blogspot.com/_hcF8ssiWKd4/ShebyVtMi2I/AAAAAAAAA_I/UIMyq5Qz2yE/s1600/add.png
- http://3.bp.blogspot.com/_hcF8ssiWKd4/Sheb0omHWVI/AAAAAAAABAo/lRslNNkzDxQ/s1600/sing.png
- http://3.bp.blogspot.com/_hcF8ssiWKd4/ShebzhZnDOI/AAAAAAAABAA/aOT2PQdIY-g/s1600/pagedes.png
- http://1.bp.blogspot.com/_hcF8ssiWKd4/Sheb0wMEVXI/AAAAAAAABAw/2t38C8NkQBc/s1600/slide.png
- http://3.bp.blogspot.com/_hcF8ssiWKd4/ShebzQoA9aI/AAAAAAAAA_o/xasQ45LJVTs/s1600/left.png
Embedded domains
- www.w3.org
- www.google.com
- www.blogger.com
- fstencilprueba.blogspot.com
- www.web2feel.com
- falconhive.com
- 1.bp.blogspot.com
- 2.bp.blogspot.com
- 3.bp.blogspot.com
- btemplates.super-red.es
- blogspot.com
- apis.google.com
- pagead2.googlesyndication.com
- themelib.com
- www.blogblog.com
Embedded IP addresses
- 52.182.143.212
- 52.253.84.76
- 4.230.171.124
- 52.110.12.22
- 52.110.12.21
- 4.247.188.224
- 184.84.165.171
- 72.145.35.111
- 52.148.114.188
- 52.110.12.18
- 52.110.12.1
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report