MALICIOUS — 97da388b05bf0ca772ddb6fde97a21eeff24852b7f4d8a252e3dda9b95ac941d
MALICIOUS — 97da388b05bf0ca772ddb6fde97a21eeff24852b7f4d8a252e3dda9b95ac941d is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (84/100). 1 of 54 detection engines flagged it.
Identification
- SHA-256:
97da388b05bf0ca772ddb6fde97a21eeff24852b7f4d8a252e3dda9b95ac941d - SHA-1:
ca0f690479246b27010ecfad56475ec73a17e2d5 - MD5:
63964b1a0da196273e164c9e0a74bd0d - ssdeep:
768:EKZb96b96b96b96b96b96b96b96b96b96b96b96b96b96b96b96b96b96b96b96n:Bb96b96b96b96b96b96b96b96b96b96H - TLSH:
T1AE329D1DFA90E5C3AD9923FA06FF1C659D52C05B7E1AFCF90CA4E54B67899B008C9108 - Submitted as: 97da388b05bf0ca772ddb6fde97a21eeff24852b7f4d8a252e3dda9b95ac941d
- File type: html · Size: 46583 bytes
- Verdict: malicious (84/100)
Detections (1 of 54 engines)
- Microsoft Defender: Trojan:JS/Redirector.AYLB!MTB
Why this verdict
The malicious score of 84/100 is the fusion of 5 weighted signals:
- Microsoft Defender flagged Trojan:JS/Redirector.AYLB!MTB (rule
Trojan:JS/Redirector.AYLB!MTB) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec (layers: char-code) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 17 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://pagead2.googlesyndication.com/pagead/show_ads.js, http://drivebleu.fr, http://voyages-sncf.mobi/ - static signal, weight 0.35, confidence 0.60
- Extracted generic config (17 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
278 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- officeclient.microsoft.com
- www.msn.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
Embedded URLs
- http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd
- http://www.w3.org/1999/xhtml
- http://pagead2.googlesyndication.com/pagead/show_ads.js
- http://drivebleu.fr
- http://voyages-sncf.mobi/
- http://wap.ratp.fr
- http://wap.pagesjaunes.fr/xhtml/
- http://m.google.com
- http://mobile.lemonde.fr
- http://iphone.20minutes.fr
- http://mobile.lefigaro.fr/serv/DFigaro
- http://m.eurosport.com
- http://m.gala.fr
- http://m.youtube.com
- http://www.messengersurvotremobile.com
- http://gameloft.mobi
- http://mobigratis.com
- http://mobile.myspace.com
- http://wap.ebay.fr
- http://fr.wap.yahoo.com
- http://www.dailymotion.com/mobile
- http://wikipedia.7val.com
- http://www.annuaire-site-mobile.com/annuaire-site-mobile.php
- http://www.annuaire-site-mobile.com/annuaire-site-iphone.php
- http://www.annuaire-site-mobile.com/annuaire-site-portable.php
Embedded domains
- www.w3.org
- pagead2.googlesyndication.com
- drivebleu.fr
- voyages-sncf.mobi
- wap.ratp.fr
- wap.pagesjaunes.fr
- m.google.com
- mobile.lemonde.fr
- iphone.20minutes.fr
- mobile.lefigaro.fr
- m.eurosport.com
- m.gala.fr
- m.youtube.com
- www.messengersurvotremobile.com
- gameloft.mobi
- mobigratis.com
- mobile.myspace.com
- wap.ebay.fr
- fr.wap.yahoo.com
- www.dailymotion.com
- wikipedia.7val.com
- www.annuaire-site-mobile.com
- siteweb.me
- www.3615dumont.com
- track.developfirstline.com
Embedded IP addresses
- 20.42.73.30
- 20.247.185.124
- 52.123.252.223
- 4.230.171.124
- 20.42.179.192
- 4.150.223.111
- 4.207.44.65
- 57.155.101.212
- 72.153.5.130
- 92.223.78.30
- 52.148.114.188
- 52.110.12.55
- 52.110.12.30
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report