MALICIOUS — 8f15690542ab569af490780a95c128226923561db9da685228b2afd982eea49f
MALICIOUS — 8f15690542ab569af490780a95c128226923561db9da685228b2afd982eea49f is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (91/100), attributed to the Cryxos family. 3 of 50 detection engines flagged it.
Identification
- SHA-256:
8f15690542ab569af490780a95c128226923561db9da685228b2afd982eea49f - SHA-1:
fc331955b0dedb0c2ff77c43f15b29dd1968ae6b - MD5:
bf175d3802a9e0de61fdccb093489aa4 - ssdeep:
48:lmI++x4S9wPTWrp5ZHkN+grQDz8HOEZHRC+Xku:1++x4mw0Hk5ExcU+T - TLSH:
T1481685DAF0CBADA8CC1C42677C04A2877A0FDF353A815BD8A74952595CE1CE81D3A022 - Submitted as: 8f15690542ab569af490780a95c128226923561db9da685228b2afd982eea49f
- File type: html · Size: 2907 bytes
- Verdict: malicious (91/100) · Family: Cryxos
Detections (3 of 50 engines)
- Microsoft Defender: Trojan:JS/Cryxos.PGCH!MTB
- Emsisoft (Emergency Kit): JS:Trojan.Cryxos.14052
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 91/100 is the fusion of 4 weighted signals:
- Microsoft Defender flagged Trojan:JS/Cryxos.PGCH!MTB (rule
Trojan:JS/Cryxos.PGCH!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged JS:Trojan.Cryxos.14052 (rule
JS:Trojan.Cryxos.14052) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd
- http://www.w3.org/1999/xhtml
Embedded domains
- www.w3.org
- window.top
More Cryxos samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report