MALICIOUS — aeb3be4f272575f3a60e6498590ea5da3c2d9372ef099bd7c4e2685b1cbf0d83
MALICIOUS — aeb3be4f272575f3a60e6498590ea5da3c2d9372ef099bd7c4e2685b1cbf0d83 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (83/100), attributed to the Redirector family. 1 of 53 detection engines flagged it.
Identification
- SHA-256:
aeb3be4f272575f3a60e6498590ea5da3c2d9372ef099bd7c4e2685b1cbf0d83 - SHA-1:
96c5e40bbb9d25a77e5cfca24fb6ecb574bbdd20 - MD5:
02d39ea91005ac2e2a235970e3e88048 - ssdeep:
1536:U61583iWNayslgaH+kv4Q8JxmavyRKvU9/KvU9lPLA444K4eDp444G4e2ouuuuu/:H5CayslgSpQpPL6RBTke26v8Xvt/S1kW - TLSH:
T17237E62467C11A8F889C5D41F5A8881C54D4AEDFE43078EAC660EF4F98BCF70A4B54A7 - Submitted as: aeb3be4f272575f3a60e6498590ea5da3c2d9372ef099bd7c4e2685b1cbf0d83
- File type: html · Size: 73021 bytes
- Verdict: malicious (83/100) · Family: Redirector
Detections (1 of 53 engines)
- Microsoft Defender: Trojan:JS/Redirector.AB!AMTB
Why this verdict
The malicious score of 83/100 is the fusion of 5 weighted signals:
- Memory forensics: 2 finding(s), e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.50, confidence 0.85 - Obfuscated powershell script: dynamic-exec, defense-evasion (layers: char-code) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 27 external host(s) at runtime (25 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://gmpg.org/xfn/11, https://twcommunicationsllc.com/xmlrpc.php, https://twcommunicationsllc.com/feed/ - static signal, weight 0.35, confidence 0.60
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
278 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- settings-win.data.microsoft.com
Embedded URLs
- http://gmpg.org/xfn/11
- https://twcommunicationsllc.com/xmlrpc.php
- https://twcommunicationsllc.com/feed/
- https://twcommunicationsllc.com/comments/feed/
- https://twcommunicationsllc.com/wp-includes/css/dist/block-library/style.min.css?ver=5.8.2
- https://twcommunicationsllc.com/wp-content/plugins/woocommerce/packages/woocommerce-blocks/build/wc-blocks-vendors-style.css?ver=5.5.1
- https://twcommunicationsllc.com/wp-content/plugins/woocommerce/packages/woocommerce-blocks/build/wc-blocks-style.css?ver=5.5.1
- https://twcommunicationsllc.com/wp-content/plugins/booked/assets/css/icons.css?ver=2.3.5
- https://twcommunicationsllc.com/wp-content/plugins/booked/assets/js/tooltipster/css/tooltipster.css?ver=3.3.0
- https://twcommunicationsllc.com/wp-content/plugins/booked/assets/js/tooltipster/css/themes/tooltipster-light.css?ver=3.3.0
- https://twcommunicationsllc.com/wp-content/plugins/booked/assets/css/animations.css?ver=2.3.5
- https://twcommunicationsllc.com/wp-content/plugins/booked/dist/booked.css?ver=2.3.5
- https://twcommunicationsllc.com/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=5.4.2
- https://twcommunicationsllc.com/wp-content/plugins/kaswara/assets/font-icon/icons.css?ver=5.8.2
- https://twcommunicationsllc.com/wp-content/plugins/kaswara/front/assets/css/style.css?ver=5.8.2
- https://twcommunicationsllc.com/wp-content/plugins/font-icons-loader/fonts/autofont/style.css?ver=5.8.2
- https://twcommunicationsllc.com/wp-content/plugins/font-icons-loader/fonts/buildfont/style.css?ver=5.8.2
- https://twcommunicationsllc.com/wp-content/plugins/font-icons-loader/fonts/elegant-icons/style.css?ver=5.8.2
- https://twcommunicationsllc.com/wp-content/plugins/font-icons-loader/fonts/finicon/style.css?ver=5.8.2
- https://twcommunicationsllc.com/wp-content/plugins/font-icons-loader/fonts/medicon/style.css?ver=5.8.2
- https://twcommunicationsllc.com/wp-content/plugins/font-icons-loader/fonts/securicon/style.css?ver=5.8.2
- https://twcommunicationsllc.com/wp-content/plugins/font-icons-loader/fonts/theme-fonts/style.css?ver=5.8.2
- https://twcommunicationsllc.com/wp-content/plugins/revslider/public/assets/css/rs6.css?ver=6.2.18
- https://twcommunicationsllc.com/wp-content/plugins/woocommerce/assets/css/woocommerce-layout.css?ver=5.6.0
- https://twcommunicationsllc.com/wp-content/plugins/woocommerce/assets/css/woocommerce-smallscreen.css?ver=5.6.0
Embedded domains
- gmpg.org
- twcommunicationsllc.com
- fonts.googleapis.com
- s.w.org
- api.w.org
- gmail.com
- tw.justjannis.com
- click.belonnanotservice.ga
Embedded IP addresses
- 20.184.175.16
- 52.123.252.233
- 4.144.132.223
- 40.84.85.40
- 4.230.171.124
- 74.178.240.61
- 135.232.92.97
- 74.178.76.128
- 20.184.175.5
- 20.231.239.246
- 52.123.128.14
- 40.104.4.2
- 52.123.129.14
- 135.233.45.223
- 52.123.252.220
- 203.26.79.13
- 52.123.252.224
- 135.233.95.80
- 52.110.12.33
- 52.110.12.56
- 52.148.114.188
- 48.199.12.1
- 20.42.65.84
- 4.150.223.105
- 72.145.35.104
More Redirector samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report