MALICIOUS — 9fe0b14c1af0acf4cee1fa9c3c9a036db51002b683ff26d8c5c4e99be1084beb
MALICIOUS — 9fe0b14c1af0acf4cee1fa9c3c9a036db51002b683ff26d8c5c4e99be1084beb is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (79/100), attributed to the Cryxos family. 2 of 51 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9fe0b14c1af0acf4cee1fa9c3c9a036db51002b683ff26d8c5c4e99be1084beb - SHA-1:
6727ded7833eb9c93a9eca8e3fd52c5bed5b94da - MD5:
e5ab98614492e5fa9a709d2509ad3b51 - ssdeep:
48:0WsBu6LICrLfkJrAkjP+D+VzrrW7b3az4lazoMNNVJJifXw6PEcljekD3e9lnl62:KuIEukyWm8JiY6HalAvwChNS - TLSH:
T1C31DA24A17AE3CFF99EC0E9D6048B0FE598F74CEA54231C026E84F4C5889DA0E0C9517 - Submitted as: 9fe0b14c1af0acf4cee1fa9c3c9a036db51002b683ff26d8c5c4e99be1084beb
- File type: html · Size: 5850 bytes
- Verdict: malicious (79/100) · Family: Cryxos
Detections (2 of 51 engines)
- Emsisoft (Emergency Kit): JS:Trojan.Cryxos.4318
- Kaspersky (KVRT): HEUR:Trojan-PSW.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 79/100 is the fusion of 5 weighted signals:
- Emsisoft (Emergency Kit) flagged JS:Trojan.Cryxos.4318 (rule
JS:Trojan.Cryxos.4318) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://motormudejar.com/, https://code.jquery.com/jquery-3.2.1.min.js - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
277 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- searchapp.bundleassets.example
- www.msftconnecttest.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- www.bing.com
- config.edge.skype.com
- desktop-hsgcbep
- tas02.sls.update.microsoft.com
- to-do.microsoft.com
- settings-win.data.microsoft.com
- dns.msftncsi.com
- ctldl.windowsupdate.com
- staging.to-do.microsoft.com
- watson.events.data.microsoft.com
- edge.microsoft.com
- aps.prod.windows.com
- teams.microsoft.com
Embedded URLs
- http://motormudejar.com/
- http://www.google.com/s2/favicons?domain=http://motormudejar.com
- https://code.jquery.com/jquery-3.2.1.min.js
- http://www.google.com/s2/favicons?domain=
Embedded domains
- motormudejar.com
- www.google.com
- code.jquery.com
- staging.to-do.officeppe.com
More Cryxos samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report