MALICIOUS — 8f12ffd34b43591b69342e634d81e90254371d6d16d632fdcee042d1c0e9c859
MALICIOUS — 8f12ffd34b43591b69342e634d81e90254371d6d16d632fdcee042d1c0e9c859 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the HideLink family. 3 of 23 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8f12ffd34b43591b69342e634d81e90254371d6d16d632fdcee042d1c0e9c859 - SHA-1:
8523381cd496b86ea1a1d2e9fe5e272df4dcd3e8 - MD5:
fb8cfd3d41b8a7abb7051584dfcb2cd5 - ssdeep:
3072:0XRYzcvbUvv9neJRuUCpRuUCL6o1oHoronoDyoXoroPocotoVRioUeoDovoDovoG:0XRYzcvbUvv9neJRuUCpRuUCLBaIModP - TLSH:
T1723C3B30A21B3E9F4854111AFF984464406CF7DF4838DAE1CA69D78EE44DC70A8AE5DE - Submitted as: 8f12ffd34b43591b69342e634d81e90254371d6d16d632fdcee042d1c0e9c859
- File type: html · Size: 115859 bytes
- Verdict: malicious (96/100) · Family: HideLink
Detections (3 of 23 engines)
- Microsoft Defender: Trojan:JS/HideLink.A
- Emsisoft (Emergency Kit): JS:Trojan.Cryxos.3521
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 8 weighted signals:
- Microsoft Defender flagged Trojan:JS/HideLink.A (rule
Trojan:JS/HideLink.A) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged JS:Trojan.Cryxos.3521 (rule
JS:Trojan.Cryxos.3521) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 57 external host(s) at runtime (21 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://www.churchwithoutwallsberkeley.org/wp-admin/admin-ajax.php, https://yoast.com/wordpress/plugins/seo/, https://www.churchwithoutwallsberkeley.org/2011/10/act-iii-gods-initiative/ - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
274 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- searchapp.bundleassets.example
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- licensing.mp.microsoft.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
Embedded URLs
- https://www.churchwithoutwallsberkeley.org/wp-admin/admin-ajax.php
- https://yoast.com/wordpress/plugins/seo/
- https://www.churchwithoutwallsberkeley.org/2011/10/act-iii-gods-initiative/
- http://www.churchwithoutwallsberkeley.org/wp-content/uploads/images/cwow-listen-now.gif
- https://schema.org
- https://www.churchwithoutwallsberkeley.org/#website
- https://www.churchwithoutwallsberkeley.org/
- https://www.churchwithoutwallsberkeley.org/2011/10/act-iii-gods-initiative/#primaryimage
- https://www.churchwithoutwallsberkeley.org/2011/10/act-iii-gods-initiative/#webpage
- https://www.churchwithoutwallsberkeley.org/#/schema/person/d938016b4b944f0ba044ecdc3938b77e
- https://www.churchwithoutwallsberkeley.org/2011/10/act-iii-gods-initiative/#breadcrumb
- https://www.churchwithoutwallsberkeley.org/#personlogo
- https://secure.gravatar.com/avatar/b2f1f8dd6ab8880a1830363e83e35e62?s=96&d=mm&r=g
- https://www.churchwithoutwallsberkeley.org/author/admin/
- https://www.churchwithoutwallsberkeley.org/feed/
- https://www.churchwithoutwallsberkeley.org/comments/feed/
- https://3z23xx4f1lfb3lbr6134lq8c-wpengine.netdna-ssl.com/wp-content/uploads/2020/07/cwow_home_logo_small.png
- https://www.churchwithoutwallsberkeley.org/2011/10/act-iii-gods-initiative/feed/
- https://www.churchwithoutwallsberkeley.org/wp-content/themes/jupiter/assets/images
- https://www.churchwithoutwallsberkeley.org/wp-content/themes/jupiter/assets/js
- https://www.churchwithoutwallsberkeley.org/wp-content/themes/jupiter
- https://www.churchwithoutwallsberkeley.org/wp-content/uploads/2020/07/cwow_home_logo-preloader.png
- https://3z23xx4f1lfb3lbr6134lq8c-wpengine.netdna-ssl.com/wp-includes/css/dist/block-library/style.min.css?ver=5.8.1
- https://3z23xx4f1lfb3lbr6134lq8c-wpengine.netdna-ssl.com/wp-content/plugins/events-manager/includes/css/events_manager.css?ver=5.9942
- https://3z23xx4f1lfb3lbr6134lq8c-wpengine.netdna-ssl.com/wp-content/plugins/seriously-simple-podcasting/assets/css/recent-episodes.css?ver=2.7.0
Embedded domains
- www.churchwithoutwallsberkeley.org
- yoast.com
- schema.org
- secure.gravatar.com
- fonts.googleapis.com
- s.w.org
- 3z23xx4f1lfb3lbr6134lq8c-wpengine.netdna-ssl.com
- api.w.org
- feeds.feedburner.com
- wp-statistics.com
- www.w3.org
- cloudpath.net
- reebokstore.co.za
- www.worlddesigncapital.com
- whiteprivilegeconference.com
- www.ims.org
- www.stcworks.ca
- vascular2013.ca
- worldjurist.net
- thecollegejuice.com
- unos.org
- buydoxycycline-norx.com
- trickoreat.ca
- buyglucophage-norx.com
- librarycopyright.net
Embedded IP addresses
- 51.104.15.252
- 52.123.252.234
- 52.230.59.222
- 52.123.252.240
- 4.247.188.233
- 52.110.12.54
- 20.76.201.171
- 4.230.171.124
- 72.145.35.101
- 135.232.92.137
- 20.42.179.204
- 20.184.175.19
- 172.178.240.163
- 52.110.12.16
- 20.112.250.133
- 20.184.175.9
- 52.110.12.15
- 135.234.160.244
- 4.247.188.224
- 52.110.12.28
- 52.110.12.19
- 4.150.223.104
- 57.154.63.210
- 74.178.240.51
- 135.233.95.144
More HideLink samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report