MALICIOUS — 8f18392b10efd1a270e7be5944268b2e49d10aaa771d6bb9900a221f871dcace
MALICIOUS — 8f18392b10efd1a270e7be5944268b2e49d10aaa771d6bb9900a221f871dcace is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100), attributed to the TrojanClicker family. 2 of 23 detection engines flagged it.
Identification
- SHA-256:
8f18392b10efd1a270e7be5944268b2e49d10aaa771d6bb9900a221f871dcace - SHA-1:
ee75b1beaf405879152d81e802b820610bf2c61c - MD5:
731b28c6182b11954269b552f498bf67 - ssdeep:
1536:ng81mimdxeSY13h3hFREQCYA5GRCvQbaAWRvk18:oRdxeSYJ1hFREQCYA5GRZzwvk18 - TLSH:
T1E73B845E33262A8F14E08952665C4EF5C0C9C5F7E93382F5E361BB89E838CB0941D997 - Submitted as: 8f18392b10efd1a270e7be5944268b2e49d10aaa771d6bb9900a221f871dcace
- File type: html · Size: 103266 bytes
- Verdict: malicious (87/100) · Family: TrojanClicker
Detections (2 of 23 engines)
- Microsoft Defender: TrojanClicker:HTML/Iframe
- Emsisoft (Emergency Kit): Trojan.JS.Agent.FCP
Why this verdict
The malicious score of 87/100 is the fusion of 4 weighted signals:
- Microsoft Defender flagged TrojanClicker:HTML/Iframe (rule
TrojanClicker:HTML/Iframe) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.JS.Agent.FCP (rule
Trojan.JS.Agent.FCP) - engine signal, weight 0.55, confidence 0.85 - Obfuscated powershell script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css, http://serigalagala.blogspot.com/favicon.ico, http://serigalagala.blogspot.com/2011/05/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.google.com/2005/gml/b
- http://www.google.com/2005/gml/data
- http://www.google.com/2005/gml/expr
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css
- http://serigalagala.blogspot.com/favicon.ico
- http://serigalagala.blogspot.com/2011/05/
- http://serigalagala.blogspot.com/feeds/posts/default
- http://serigalagala.blogspot.com/feeds/posts/default?alt=rss
- https://www.blogger.com/feeds/5365158294980165557/posts/default
- http://randaclay.com
- http://techprevue.blogspot.com
- http://img132.imageshack.us/img132/7414/header2f.jpg
- http://4.bp.blogspot.com/_jA-SP6SAtfY/SrCOsBgFT6I/AAAAAAAABNo/mRr1xtkBjMw/s1600/header1y.jpg
- https://www.blogger.com/dyn-css/authorization.css?targetBlogID=5365158294980165557&
- https://apis.google.com/js/plusone.js
- http://serigalagala.blogspot.com/
- http://serigalagala.blogspot.com/feeds/comments/default
- http://blogger.com
- http://scripts.widgethost.com/pax/counter.js?counter=ctr-r7qrw6l57n
- http://www.pax.com/free-counters.html
- http://counter.pax.com/counter/image?counter=ctr-r7qrw6l57n&noscript=1
- http://www.widgeo.net/message.php?msg=Fuad
- http://www.widgeo.net
- http://www.widgeo.net/img/logopm.png
Embedded domains
- www.w3.org
- www.google.com
- www.blogger.com
- serigalagala.blogspot.com
- randaclay.com
- techprevue.blogspot.com
- img132.imageshack.us
- 4.bp.blogspot.com
- blogspot.com
- apis.google.com
- pagead2.googlesyndication.com
- blogger.com
- scripts.widgethost.com
- www.pax.com
- counter.pax.com
- www.widgeo.net
- widgeo.net
- 2.bp.blogspot.com
- www.gstatic.com
- 3.bp.blogspot.com
- 1.bp.blogspot.com
- ja.revolvermaps.com
- cdn.widgetserver.com
- www.widgetbox.com
- docs.widgetbox.com
More TrojanClicker samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report