MALICIOUS — 990754a4faf3c6794699c75bb61b0a5ab6b4ce2d7d699c7c2c2f9ba5580e8eef
MALICIOUS — 990754a4faf3c6794699c75bb61b0a5ab6b4ce2d7d699c7c2c2f9ba5580e8eef is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (84/100), attributed to the TrojanClicker family. 2 of 53 detection engines flagged it.
Identification
- SHA-256:
990754a4faf3c6794699c75bb61b0a5ab6b4ce2d7d699c7c2c2f9ba5580e8eef - SHA-1:
48e66b120b684e513e6da749512385b44ccbe2c2 - MD5:
dc44a9363008f3d5114b5280ba0e207c - ssdeep:
768:fZ13JcLAyHHHW8o8snpbPRQCbPhwOYH+hwOYHVvA72yWITxHesP:WLJHH28ZsntPRQAuOYeuOYlA7hDtHBP - TLSH:
T16536960C7E793A420C808423B6ED5EEAC2D551639633C2B5E563DF84D2A9E20AF55DC3 - Submitted as: 990754a4faf3c6794699c75bb61b0a5ab6b4ce2d7d699c7c2c2f9ba5580e8eef
- File type: html · Size: 65721 bytes
- Verdict: malicious (84/100) · Family: TrojanClicker
Detections (2 of 53 engines)
- Microsoft Defender: TrojanClicker:JS/Faceliker!rfn
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 84/100 is the fusion of 5 weighted signals:
- Memory forensics: 3 finding(s), e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 20 external host(s) at runtime (23 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1667664774-css_bundle_v2.css, http://www.blogblog.com/1kt/simple/gradients_light.png, http://www.blogblog.com/1kt/simple/body_gradient_tile_light.png - static signal, weight 0.35, confidence 0.60
- Extracted generic config (14 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
277 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.google.com/2005/gml/b
- http://www.google.com/2005/gml/data
- http://www.google.com/2005/gml/expr
- https://www.blogger.com/static/v1/widgets/1667664774-css_bundle_v2.css
- http://www.blogblog.com/1kt/simple/gradients_light.png
- http://www.blogblog.com/1kt/simple/body_gradient_tile_light.png
- https://www.blogger.com/dyn-css/authorization.css?targetBlogID=7107654827061385894&
- https://apis.google.com/js/plusone.js
- https://satilikkurbanlikfiyatlari.blogspot.com/
- https://pagead2.googlesyndication.com/pagead/js/adsbygoogle.js
- https://www.blogger.com/post-edit.g?blogID=7107654827061385894&postID=6950246762368749946&from=pencil
- https://resources.blogblog.com/img/icon18_edit_allbkg.gif
- https://www.blogger.com/share-post.g?blogID=7107654827061385894&postID=6950246762368749946&target=email
- https://www.blogger.com/share-post.g?blogID=7107654827061385894&postID=6950246762368749946&target=blog
- https://www.blogger.com/share-post.g?blogID=7107654827061385894&postID=6950246762368749946&target=twitter
- https://www.blogger.com/share-post.g?blogID=7107654827061385894&postID=6950246762368749946&target=facebook
- https://www.blogger.com/share-post.g?blogID=7107654827061385894&postID=6950246762368749946&target=pinterest
- https://satilikkurbanlikfiyatlari.blogspot.com/search/label/2013%20kurbanl%C4%B1k
- https://satilikkurbanlikfiyatlari.blogspot.com/search/label/2013%20kurbanl%C4%B1k%20fiyatlar%C4%B1
- https://satilikkurbanlikfiyatlari.blogspot.com/search/label/Bal%C4%B1kesir%20Kurbanl%C4%B1k%20Fiyatlar%C4%B1
- https://satilikkurbanlikfiyatlari.blogspot.com/search/label/kurban%20bayram%C4%B1%20kurbanl%C4%B1k
- https://satilikkurbanlikfiyatlari.blogspot.com/search/label/kurban%20bayram%C4%B1%20kurbanl%C4%B1k%20fiyatlar%C4%B1
- https://satilikkurbanlikfiyatlari.blogspot.com/search/label/kurbanl%C4%B1k
- https://www.blogger.com/comment-iframe.g?blogID=7107654827061385894&postID=6950246762368749946
Embedded domains
- www.w3.org
- www.google.com
- www.blogger.com
- www.noaesthetic.com
- www.blogblog.com
- header.shadow.offset.top
- tabs.margin.top
- main.padding.top
- blogspot.com
- apis.google.com
- satilikkurbanlikfiyatlari.blogspot.com
- pagead2.googlesyndication.com
- resources.blogblog.com
- ciddievliliksitesi.net
- 3.bp.blogspot.com
- www.facebook.com
- like.style.top
- www.haberingiltere.uk
- www.google.com.tr
Embedded IP addresses
- 13.89.179.15
- 57.155.101.212
- 4.230.171.124
- 4.144.132.114
- 74.178.240.61
- 20.184.175.17
- 74.178.240.51
- 20.76.201.171
- 52.123.128.14
- 172.178.240.162
- 135.233.95.80
- 203.26.79.13
- 52.148.114.188
- 125.56.205.123
- 125.56.205.17
- 48.211.4.16
- 72.145.35.99
- 74.178.232.29
- 52.110.12.16
- 52.110.12.37
More TrojanClicker samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report