MALICIOUS — 99047e62509742f223b51bc4e87cac3dfd1e21251f74ba48e8133ab4cb2e8add
MALICIOUS — 99047e62509742f223b51bc4e87cac3dfd1e21251f74ba48e8133ab4cb2e8add is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (84/100), attributed to the TrojanClicker family. 2 of 53 detection engines flagged it.
Identification
- SHA-256:
99047e62509742f223b51bc4e87cac3dfd1e21251f74ba48e8133ab4cb2e8add - SHA-1:
be6e63c86e0d3f903171bbc0f983f110a51139c7 - MD5:
52b78279e1a34a611618fe4e3b8672c7 - ssdeep:
768:layHHvPWlfjFwSP4wyihL/OiCoJLkJCh:l3HH2lfjFwi4wzmiCALkJs - TLSH:
T13732B9463765B68608D084169A5C8AC9B0CAC257FE3392F5E277FF49D43CC70A81AD87 - Submitted as: 99047e62509742f223b51bc4e87cac3dfd1e21251f74ba48e8133ab4cb2e8add
- File type: html · Size: 44591 bytes
- Verdict: malicious (84/100) · Family: TrojanClicker
Detections (2 of 53 engines)
- Microsoft Defender: TrojanClicker:JS/Faceliker.N
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 84/100 is the fusion of 5 weighted signals:
- Memory forensics: 3 finding(s), e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec, defense-evasion (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 27 external host(s) at runtime (27 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1667664774-css_bundle_v2.css, http://ruhesinizicekin.blogspot.com/favicon.ico, http://ruhesinizicekin.blogspot.com/feeds/posts/default - static signal, weight 0.35, confidence 0.60
- Extracted generic config (16 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
280 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
Embedded URLs
- https://www.blogger.com/static/v1/widgets/1667664774-css_bundle_v2.css
- http://ruhesinizicekin.blogspot.com/favicon.ico
- http://ruhesinizicekin.blogspot.com/2012/03/benlik-saygsn-artrmann-yollar.html
- http://ruhesinizicekin.blogspot.com/feeds/posts/default
- http://ruhesinizicekin.blogspot.com/feeds/posts/default?alt=rss
- https://www.blogger.com/feeds/290761532130847552/posts/default
- http://ruhesinizicekin.blogspot.com/feeds/501151836051400574/comments/default
- https://www.blogger.com/static/v1/jsbin/403901366-ieretrofit.js
- https://resources.blogblog.com/blogblog/data/1kt/simple/body_gradient_tile_light.png
- https://resources.blogblog.com/blogblog/data/1kt/simple/gradients_light.png
- https://www.blogger.com/dyn-css/authorization.css?targetBlogID=290761532130847552&
- https://apis.google.com/js/plusone.js
- http://ruhesinizicekin.blogspot.com/
- http://schema.org/BlogPosting
- http://www.kisiselgelisimveolumlamalar.com/ozguven-guclendirici-telkinli-mp3/benlik-saygisini-artirmanin-yollari-t3332.0.html#.T1BydaOb6NM.blogger
- http://schema.org/Person
- https://www.blogger.com/profile/10032023011232675575
- https://www.blogger.com/post-edit.g?blogID=290761532130847552&postID=501151836051400574&from=pencil
- https://resources.blogblog.com/img/icon18_edit_allbkg.gif
- https://www.blogger.com/share-post.g?blogID=290761532130847552&postID=501151836051400574&target=email
- https://www.blogger.com/share-post.g?blogID=290761532130847552&postID=501151836051400574&target=blog
- https://www.blogger.com/share-post.g?blogID=290761532130847552&postID=501151836051400574&target=twitter
- https://www.blogger.com/share-post.g?blogID=290761532130847552&postID=501151836051400574&target=facebook
- https://www.blogger.com/share-post.g?blogID=290761532130847552&postID=501151836051400574&target=pinterest
- https://www.blogger.com/comment-iframe.g?blogID=290761532130847552&postID=501151836051400574
Embedded domains
- www.blogger.com
- ruhesinizicekin.blogspot.com
- resources.blogblog.com
- blogspot.com
- apis.google.com
- pagead2.googlesyndication.com
- schema.org
- www.kisiselgelisimveolumlamalar.com
- www.facebook.com
- like.style.top
- www.gstatic.com
- www.blogblog.com
Embedded IP addresses
- 20.184.175.21
- 20.247.184.197
- 4.230.171.124
- 85.210.196.11
- 4.247.188.233
- 74.178.240.61
- 4.150.223.101
- 135.233.95.135
- 52.123.128.14
- 20.112.250.133
- 40.99.133.242
- 52.123.129.14
- 52.123.252.226
- 203.26.79.13
- 172.178.240.163
- 172.66.2.5
- 74.179.71.159
- 52.123.252.222
- 52.148.114.188
- 92.223.78.30
- 172.170.180.133
- 20.42.72.131
- 4.150.223.114
- 72.145.35.110
- 20.42.73.27
More TrojanClicker samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report