MALICIOUS — 990dff7ba8267b11d35402e8acab13d6db2036756434641bf196461acc07f52a
MALICIOUS — 990dff7ba8267b11d35402e8acab13d6db2036756434641bf196461acc07f52a is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the Obfus family. 4 of 53 detection engines flagged it.
Identification
- SHA-256:
990dff7ba8267b11d35402e8acab13d6db2036756434641bf196461acc07f52a - SHA-1:
05b29cd6043034ca44de5270d7f5c4fbfd7a00e0 - MD5:
58e7d308a27d8adb812f6556913e09d1 - ssdeep:
768:pZhanPtPAGnf1/siOk4BaZFLvH9mLyZSsBiiiAiinLSgVHbis4viZekQoLCWgl:pZaVPPnf1/siOkxtH9mLyZSsBiiiAiik - TLSH:
T1D431EC59B716699FE4483006D46C39FC44D9F3C7EE2058E4E6B4EF482D18EB4701A4AB - Submitted as: 990dff7ba8267b11d35402e8acab13d6db2036756434641bf196461acc07f52a
- File type: html · Size: 42594 bytes
- Verdict: malicious (96/100) · Family: Obfus
Detections (4 of 53 engines)
- ClamAV (daily): Js.Trojan.Obfus-633
- Microsoft Defender: Trojan:JS/HideLink.A
- Emsisoft (Emergency Kit): Trojan.Script.641484
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Js.Trojan.Obfus-633 (rule
Js.Trojan.Obfus-633) - engine signal, weight 0.90, confidence 0.95 - Obfuscated javascript script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 27 external host(s) at runtime (27 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://blog.a3cfestival.com/hubfs/favicon-96x96.png, https://fonts.googleapis.com/css?family=Fauna+One, https://blog.a3cfestival.com/hs-fs/hub/73154/hub_generated/template_assets/5367577842/1569759215174/Coded_files/Custom/page/2017/pop-up-div.js - static signal, weight 0.35, confidence 0.60
- Extracted generic config (16 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
279 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- licensing.mp.microsoft.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
Embedded URLs
- https://blog.a3cfestival.com/hubfs/favicon-96x96.png
- https://cdnjs.cloudflare.com/ajax/libs/trianglify/0.2.1/trianglify.min.js
- https://fonts.googleapis.com/css?family=Fauna+One
- https://blog.a3cfestival.com/hs-fs/hub/73154/hub_generated/template_assets/5367577842/1569759215174/Coded_files/Custom/page/2017/pop-up-div.js
- https://connect.facebook.net/en_US/fbevents.js
- https://www.facebook.com/tr?id=382502488894767&
- https://www.facebook.com/tr?id=257763715058112&
- http://blog.a3cfestival.com/post/news/style-village-vendor-born-fly?hs_amp=true
- http://blog.a3cfestival.com/hs-fs/hub/73154/file-2500758454-png/blog-files/bornfly-e1380165917379.png#keepProtocol
- http://blog.a3cfestival.com/post/news/style-village-vendor-born-fly
- https://blog.a3cfestival.com/hs-fs/hub/73154/hub_generated/template_assets/350626924/1569759209924/Coded_files/Custom/page/css/Style2014.min.css
- https://blog.a3cfestival.com/hs-fs/hub/73154/hub_generated/template_assets/3433158973/1569759212185/Coded_files/Custom/page/css/style2016.min.css
- https://blog.a3cfestival.com/hs-fs/hub/73154/hub_generated/template_assets/4250661537/1569759211811/Coded_files/Custom/page/css/Blog2016.min.css
- https://blog.a3cfestival.com/hs-fs/hub/73154/hub_generated/template_assets/4860016775/1569759212792/Coded_files/Custom/page/css/style2017.min.css
- https://www.a3cfestival.com
- https://a3cconference.com/shows/index.html
- https://a3cconference.com/lineup/index.html
- https://udxsva.com/tag?id=11009
- http://researchpaperwritingservicee.com/writing-research-paper/
- http://born-fly.com/
- https://blog.a3cfestival.com/hs-fs/hubfs/Logo%202019/A3C_15_BADGE_STROKE_BLK@3x.png?width=350&
- https://blog.a3cfestival.com/hs-fs/hubfs/Logo%202019/A3C_15_BADGE_STROKE_BLK@3x.png?width=175&
- https://blog.a3cfestival.com/hs-fs/hubfs/Logo%202019/A3C_15_BADGE_STROKE_BLK@3x.png?width=525&
- https://blog.a3cfestival.com/hs-fs/hubfs/Logo%202019/A3C_15_BADGE_STROKE_BLK@3x.png?width=700&
- https://blog.a3cfestival.com/hs-fs/hubfs/Logo%202019/A3C_15_BADGE_STROKE_BLK@3x.png?width=875&
Embedded domains
- blog.a3cfestival.com
- maxcdn.bootstrapcdn.com
- cdnjs.cloudflare.com
- fonts.googleapis.com
- connect.facebook.net
- www.facebook.com
- platform.linkedin.com
- cdn2.hubspot.net
- www.a3cfestival.com
- a3cconference.com
- udxsva.com
- go.a3cfestival.com
- researchpaperwritingservicee.com
- born-fly.com
- www.ihg.com
- twitter.com
- www.youtube.com
- instagram.com
- js.hsforms.net
- app.hubspot.com
- cp.hubspot.com
- s7.addthis.com
- www.addthis.com
- example.com
- s.adroll.com
Embedded IP addresses
- 4.150.223.111
- 52.230.59.222
- 4.230.171.124
- 40.84.85.40
- 4.247.188.224
- 74.178.240.61
- 20.184.175.18
- 74.178.76.54
- 20.76.201.171
- 52.123.128.14
- 52.123.129.14
- 20.50.201.195
- 135.233.45.223
- 203.26.79.13
- 20.165.94.46
- 52.110.12.21
- 52.110.12.40
- 52.148.114.188
- 142.250.183.35
- 4.150.223.99
- 20.42.65.91
- 72.154.7.107
- 48.200.63.27
- 51.116.246.105
- 172.215.188.232
More Obfus samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report