MALICIOUS — ad13fe15582def936d8edae946492709ad62f6201d59b719dc4f6277aa4b2faa
MALICIOUS — ad13fe15582def936d8edae946492709ad62f6201d59b719dc4f6277aa4b2faa is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (85/100), attributed to the Smuggling family. 1 of 53 detection engines flagged it.
Identification
- SHA-256:
ad13fe15582def936d8edae946492709ad62f6201d59b719dc4f6277aa4b2faa - SHA-1:
83af9a7be29db1cdc4b3e76bd939655c8b8ddee9 - MD5:
e0d95cd834ef968c8d2a998aaf8cba7a - ssdeep:
6144:/cRzLK+nUdO6jcvNrJ3lsLftEC5rJ3GsLf/f1sm28q+3ASL/bk:qKCFrJ3+fymrJ3bfH1sa3u - TLSH:
T1554E6C63F8AB6EC5DC6E90AD7EDCE67C25D4AC55682705D842E4C3C118208B2CBC796C - Submitted as: ad13fe15582def936d8edae946492709ad62f6201d59b719dc4f6277aa4b2faa
- File type: html · Size: 641950 bytes
- Verdict: malicious (85/100) · Family: Smuggling
Detections (1 of 53 engines)
- YARA: delivr.to detections: DLV_HTML_Smuggling
Why this verdict
The malicious score of 85/100 is the fusion of 6 weighted signals:
- YARA: delivr.to detections flagged DLV_HTML_Smuggling (rule
DLV_HTML_Smuggling) - engine signal, weight 0.70, confidence 0.70 - Obfuscated javascript script: dynamic-exec, defense-evasion (layers: base64) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 30 external host(s) and 27 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://static.parastorage.com/client/pfavico.ico, https://static.parastorage.com/unpkg/core-js-bundle@3.2.1/minified.js, https://static.parastorage.com/unpkg/focus-within-polyfill@5.0.9/dist/focus-within-polyfill.js - static signal, weight 0.35, confidence 0.60
- Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
286 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
Embedded URLs
- https://static.parastorage.com/client/pfavico.ico
- https://static.parastorage.com/unpkg/core-js-bundle@3.2.1/minified.js
- https://static.parastorage.com/unpkg/focus-within-polyfill@5.0.9/dist/focus-within-polyfill.js
- https://polyfill.io/v3/polyfill.min.js?features=fetch
- https://static.parastorage.com/services/wix-thunderbolt/dist/webpack-runtime.2bea2a09.bundle.min.js
- https://static.parastorage.com/services/wix-thunderbolt/dist/
- https://static.parastorage.com/services/wix-thunderbolt/dist/webpack-runtime.2bea2a09.bundle.min.js.map
- https://static.parastorage.com/services/wix-thunderbolt/dist/browser-deprecation.inline.dd78f89a.bundle.min.js
- https://static.parastorage.com/services/wix-thunderbolt/dist/deprecation-
- https://static.parastorage.com/services/wix-thunderbolt/dist/browser-deprecation.inline.dd78f89a.bundle.min.js.map
- https://static.parastorage.com/services/editor-elements/dist/
- https://static.parastorage.com/services/wix-thunderbolt/dist/tslib.inline.59e9085d.bundle.min.js
- https://static.parastorage.com/services/wix-thunderbolt/dist/tslib.inline.59e9085d.bundle.min.js.map
- https://static.parastorage.com/services/wix-thunderbolt/dist/bi-common.inline.ad8aab1f.bundle.min.js
- https://frog.wix.com/bt
- https://static.parastorage.com/services/wix-thunderbolt/dist/bi-common.inline.ad8aab1f.bundle.min.js.map
- https://static.parastorage.com/services/wix-thunderbolt/dist/sendFedopsLoadStarted.inline.cb06a6d1.bundle.min.js
- https://browser.sentry-cdn.com/6.13.3/bundle.min.js
- https://605a7baede844d278b89dc95ae0a9123@sentry-next.wixpress.com/68
- https://static.parastorage.com/services/wix-thunderbolt/dist/externals-registry.inline.faff0158.bundle.min.js
- https://static.parastorage.com/services/wix-thunderbolt/dist/externals-registry.inline.faff0158.bundle.min.js.map
- https://static.parastorage.com/services/wix-thunderbolt/dist/bi.inline.cf9319d3.bundle.min.js
- https://static.parastorage.com/services/wix-thunderbolt/dist/bi.inline.cf9319d3.bundle.min.js.map
- https://static.parastorage.com/services/wix-thunderbolt/dist/createPlatformWorker.inline.67b589fd.bundle.min.js
- https://bo.wix.com/suricate/
Embedded domains
- static.parastorage.com
- polyfill.io
- i.name
- wix.com
- browseroutofdateios.com
- browseroutofdateand.com
- browseroutofdatedes.com
- www.blogdatvmenorah.com
- e.name
- frog.wix.com
- i.site
- window.top
- e.site
- browser.sentry-cdn.com
- sentry-next.wixpress.com
- static.wixstatic.com
- video.wixstatic.com
- blogdatvmenorah.com
- vod-server.wix.com
- sentry.wixpress.com
- so-feed.codev.wixapps.net
- engage.wixapps.net
- statcounter.va-endpoint.com
- app.visitor-analytics.io
- gs.wixapps.net
Embedded IP addresses
- 52.123.252.236
- 20.42.73.30
- 4.230.171.124
- 172.215.188.225
- 52.230.60.54
- 74.178.240.61
- 52.168.117.175
- 74.178.76.54
- 20.76.201.171
- 52.123.128.14
- 52.123.129.14
- 4.150.223.112
- 135.233.45.222
- 52.123.252.234
- 52.123.252.222
- 74.178.76.44
- 203.26.79.13
- 52.148.114.188
- 52.110.12.55
- 52.110.12.50
- 184.84.165.171
- 184.84.165.136
- 48.192.143.121
- 52.168.112.67
- 20.42.73.28
More Smuggling samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report