MALICIOUS — virussign.com_70c33cfe9e9cff147a4885ffd3828580.vir
MALICIOUS — virussign.com_70c33cfe9e9cff147a4885ffd3828580.vir is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (77/100), attributed to the Smuggling family. 1 of 53 detection engines flagged it.
Identification
- SHA-256:
9f61ec03b9375a51ecfd89494fe5cddaf1ad1c758f48eae2a3b6f6bd9fddcce5 - SHA-1:
a91e6c9ab4d169da8a2993b245d2acd0b7e216bc - MD5:
70c33cfe9e9cff147a4885ffd3828580 - ssdeep:
6144:FiqSZKugg15aTwh3jaK+QipSbrwRuJWye7C0YLYQY4Kugg15aTwn/kqk63De3IPh:5ugg15aTw5iobeAZwugg15aTwb - TLSH:
T12250FA12A3AB8E97D8C1294EF1582CE80C4DFAE34F111DE6826DDB4D09D46749C8BCE5 - Submitted as: virussign.com_70c33cfe9e9cff147a4885ffd3828580.vir
- File type: html · Size: 820156 bytes
- Verdict: malicious (77/100) · Family: Smuggling
Source: VirusSign · first seen 2026-08-19T00:00:00.000Z · SHA-256 verified
Detections (1 of 53 engines)
- YARA: delivr.to detections: DLV_HTML_Smuggling
Why this verdict
The malicious score of 77/100 is the fusion of 5 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 30 external host(s) at runtime (30 HTTP) - network signal, weight 0.40, confidence 0.80
- YARA: delivr.to detections flagged DLV_HTML_Smuggling (rule
DLV_HTML_Smuggling) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ogp.me/ns#, https://ezopet.com/xmlrpc.php, https://ezopet.com/wp-content/themes/martfury/fonts/linearicons.woff2 - static signal, weight 0.35, confidence 0.60
- Extracted generic config (17 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
287 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- c.pki.goog
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- licensing.mp.microsoft.com
- windows.msn.com
- oneocsp.microsoft.com
Embedded URLs
- https://ogp.me/ns#
- https://ezopet.com/xmlrpc.php
- https://ezopet.com/wp-content/themes/martfury/fonts/linearicons.woff2
- https://ezopet.com/wp-content/themes/martfury/fonts/eleganticons.woff2
- https://ezopet.com/wp-content/themes/martfury/fonts/ionicons.woff2
- https://rankmath.com/
- https://ezopet.com/
- https://schema.org
- https://ezopet.com/#organization
- https://ezopet.com
- https://ezopet.com/#website
- https://ezopet.com/wp-content/uploads/2025/12/S8f2373cb169041abb10d4106d72b4932W-300x300.jpg
- https://ezopet.com/#webpage
- https://ezopet.com/author/ezopet/
- https://secure.gravatar.com/avatar/2bcbcb5392fc241c2a34cc497dec9ecee461027c06410283cb579834a1a1486d?s=96&
- https://ezopet.abcibd.com
- https://ezopet.com/#richSnippet
- https://ezopet.com/feed/
- https://ezopet.com/comments/feed/
- https://ezopet.com/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fezopet.com%2F
- https://ezopet.com/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fezopet.com%2F&
- https://ezopet.com/wp-content/plugins/woocommerce/assets/client/blocks/wc-blocks.css?ver=wc-10.3.8
- https://ezopet.com/wp-content/uploads/font-awesome/v7.1.0/css/svg-with-js.css
- https://ezopet.com/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=6.1.4
- https://ezopet.com/wp-content/plugins/woocommerce/assets/css/woocommerce.css?ver=10.3.8
Embedded domains
- ogp.me
- ezopet.com
- rankmath.com
- schema.org
- secure.gravatar.com
- ezopet.abcibd.com
- use.fontawesome.com
- fonts.googleapis.com
- random-affiliate.atimaze.com
- images.purevpnaffiliates.com
- s-img.adskeeper.com
- paid.outbrain.com
- wallpaperaccess.com
- body.no
- rcm-fe.amazon-adsystem.com
- div.app
- div.cc
- div.dev
- div.edu
- div.eu
- api.w.org
- fonts.gstatic.com
- t.style.top
- gsap.to
- o.c.module.style.top
Embedded IP addresses
- 20.42.73.28
- 52.123.252.247
- 4.144.132.114
- 4.230.171.124
- 172.215.188.225
- 57.155.101.212
- 135.232.92.137
- 135.232.92.34
- 135.233.95.135
- 51.132.193.104
- 203.26.79.13
- 20.112.250.133
- 52.123.129.14
- 52.123.128.14
- 135.233.45.221
- 52.148.114.188
- 52.168.117.169
- 20.42.65.89
- 162.159.142.9
- 72.154.7.109
- 172.170.180.133
- 20.184.175.8
- 52.178.17.233
- 4.150.223.98
- 4.150.223.107
More Smuggling samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report