MALICIOUS — 8d6a96e7ea7a536ca9d443f6c43bd43ec3dfd529180a945d6bbb7b912e192417
MALICIOUS — 8d6a96e7ea7a536ca9d443f6c43bd43ec3dfd529180a945d6bbb7b912e192417 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the Blacklisted family. 1 of 54 detection engines flagged it.
Identification
- SHA-256:
8d6a96e7ea7a536ca9d443f6c43bd43ec3dfd529180a945d6bbb7b912e192417 - SHA-1:
0f2f8743d441a2ffdbbedc6a2baff18b4e02fb8a - MD5:
5af5206f69b60396f2ead26ca9518bfe - ssdeep:
768:GswAvT8wNrS0dFWBFXjn1ywxJaXRT1ZanTLNCfzwpX7RzwpmlRePT0yobN21wZLH:GFAvT8300Yq0zBcN+peMG29o - TLSH:
T1443E30256BE1384E18BD2216E004C8A46C88FD27D51AF8D2473D8F970519F376CB9A9F - Submitted as: 8d6a96e7ea7a536ca9d443f6c43bd43ec3dfd529180a945d6bbb7b912e192417
- File type: html · Size: 139782 bytes
- Verdict: malicious (96/100) · Family: Blacklisted
Detections (1 of 54 engines)
- ClamAV feed: InterServer (malware): sigs.InterServer.net.HEX.Topline.blacklisted.domain.quantsa.ru.809.UNOFFICIAL
Why this verdict
The malicious score of 96/100 is the fusion of 6 weighted signals:
- ClamAV feed: InterServer (malware) flagged sigs.InterServer.net.HEX.Topline.blacklisted.domain.quantsa.ru.809.UNOFFICIAL (rule
sigs.InterServer.net.HEX.Topline.blacklisted.domain.quantsa.ru.809.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://dle-news.ru, http://www.audiclub-russia.ru/engine/opensearch.php, http://www.audiclub-russia.ru/user/ozEFizbt/rss.xml - static signal, weight 0.35, confidence 0.60
- Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
283 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- edge.microsoft.com
- time.windows.com
- settings-win.data.microsoft.com
- geo.prod.do.dsp.mp.microsoft.com
Embedded URLs
- http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd
- http://www.w3.org/1999/xhtml
- http://dle-news.ru
- http://www.audiclub-russia.ru/engine/opensearch.php
- http://www.audiclub-russia.ru/user/ozEFizbt/rss.xml
- https://staticsfs.host/js/EQHAwxADAgAUxAGSVlFL1FZe4jCL0hEFAQdK1gQFJhAyAgTdByDtISJTsEWA5DOzcRLi42KmcUO-IEPnkyHGphQXpQE-cxYm0yXTgVNEQzI8gRFlUUKYojUHRjYxQBOZoRQNMANuMFMvcXFAIDMGYBWPAFHCtAXUIQQBAwCWtFQHlBFJ9xTVYwO.js?tds=3&trl=0.50
- http://quantsa.ru/?de
- http://www.audi.de/bin/dpu-de/
- http://acc-6.audi.de
- http://mediaservice.audi.com/media
- http://www.audi.de/content/dam/ngw/product/model_navigation/my_2014/flyouts_2014/550x274_0000_A1.png
- http://www.audi.de/content/dam/ngw/product/model_navigation/my_2014/flyouts_2014/550x274_0001_A1_Sportback.png
- http://www.audi.de/content/dam/ngw/product/model_navigation/my_2014_new_render_images/550x274_RIO_flyout.png
- http://www.audi.de/content/dam/ngw/product/model_navigation/my_2014_new_render_images/550x274_MIAMI_flyout.png
- http://www.audi.de/content/dam/ngw/product/model_navigation/my_2014/flyouts_2014/550x247_0048_A3_final.png
- http://www.audi.de/content/dam/ngw/product/model_navigation/my_2014_new_render_images/550x274_0002_a3_limousine.png
- http://www.audi.de/content/dam/ngw/product/model_navigation/my_2014/flyouts_2014/550x247_0046_A3_Sportback_final.png
- http://www.audi.de/content/dam/ngw/product/model_navigation/my_2014/flyouts_2014/A3_Cabriolet_440x274.png
- http://www.audi.de/content/dam/ngw/product/model_navigation/my_2014/flyouts_2014/550x247_0047_S3_final.png
- http://www.audi.de/content/dam/ngw/product/model_navigation/my_2014/flyouts_2014/550x247_0045_S3_Sportback_final.png
- http://www.audi.de/content/dam/ngw/product/model_navigation/my_2014/flyouts_2014/550x247_0049_S3_Limousine_final.png
- http://www.audi.de/content/dam/ngw/product/model_navigation/my_2014/flyouts_2014/550x274_0008_A4_Limousine.png
- http://www.audi.de/content/dam/ngw/product/model_navigation/my_2014/flyouts_2014/550x274_0009_A4_Avant.png
- http://www.audi.de/content/dam/ngw/product/model_navigation/my_2014/flyouts_2014/550x274_0013_A4_allroad_quattro.png
- http://www.audi.de/content/dam/ngw/product/model_navigation/my_2014/flyouts_2014/550x274_0012_S4_Limousine.png
Embedded domains
- www.w3.org
- dle-news.ru
- www.audiclub-russia.ru
- quantsa.ru
- vuryua.ru
- www.audi.de
- acc-6.audi.de
- mediaservice.audi.com
- www.audi-motorsport.com
- vtp.audi.com
- shops.audi.com
- microsites-secure.audi.com
- microsites.audi.com
- damskoe.ru
- gmail.com
- audi.de
- staticsfs.host
Embedded IP addresses
- 20.184.175.9
- 20.247.184.197
- 4.230.171.124
- 40.84.85.40
- 52.110.12.40
- 52.110.12.14
- 52.148.114.188
- 72.154.7.107
More Blacklisted samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report