MALICIOUS — b6e105c49523177a04f65400536984e35083f99b9597f92566a446f39ef5a3ce
MALICIOUS — b6e105c49523177a04f65400536984e35083f99b9597f92566a446f39ef5a3ce is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the Gootloader family. 3 of 54 detection engines flagged it.
Identification
- SHA-256:
b6e105c49523177a04f65400536984e35083f99b9597f92566a446f39ef5a3ce - SHA-1:
1485ec3166f36edf0ed60b66acd2fc8e44221ac0 - MD5:
a3eb44e8a48d5a33bc970b82649366c2 - ssdeep:
6144:l4yBGBFBQBeB2BBFqJjxBIa5IVz7ESXXDyJuCbhaJwAY:qyBGBFBQBeB2Br+mzlytNAY - TLSH:
T153463A9B3A5CBDCDC84D01A77DE8166DA2834E1BF46981DCD2B9E748E820DB0584DC6C - Submitted as: b6e105c49523177a04f65400536984e35083f99b9597f92566a446f39ef5a3ce
- File type: html · Size: 296078 bytes
- Verdict: malicious (96/100) · Family: Gootloader
Detections (3 of 54 engines)
- YARA: SophosLabs IoCs (public): SOPHOS_Gootloader_JS
- Microsoft Defender: TrojanClicker:JS/Faceliker.N
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 96/100 is the fusion of 7 weighted signals:
- YARA: SophosLabs IoCs (public) flagged SOPHOS_Gootloader_JS (rule
SOPHOS_Gootloader_JS) - engine signal, weight 0.70, confidence 0.70 - Microsoft Defender flagged TrojanClicker:JS/Faceliker.N (rule
TrojanClicker:JS/Faceliker.N) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec, defense-evasion (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 2 external host(s) and 18 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css, http://fonts.googleapis.com/css?family=Oswald, http://fonts.googleapis.com/css?family=PT+Sans+Narrow - static signal, weight 0.35, confidence 0.60
- Extracted generic config (14 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
288 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- licensing.mp.microsoft.com
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.google.com/2005/gml/b
- http://www.google.com/2005/gml/data
- http://www.google.com/2005/gml/expr
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css
- http://fonts.googleapis.com/css?family=Oswald
- http://fonts.googleapis.com/css?family=PT+Sans+Narrow
- http://fullpornolariizle.blogspot.com/favicon.ico
- http://fullpornolariizle.blogspot.com/
- http://fullpornolariizle.blogspot.com/feeds/posts/default
- http://fullpornolariizle.blogspot.com/feeds/posts/default?alt=rss
- https://www.blogger.com/feeds/909202517349045073/posts/default
- https://www.blogger.com/profile/15562711268528922200
- http://3.bp.blogspot.com/-lSNZsuJNw-Y/ULITlX814FI/AAAAAAAAI2k/liRqSzbSgzI/s150/onizleme.png
- http://www.maskolis.com/
- http://3.bp.blogspot.com/-KSFSoZbUyyA/T-OYyR7Tp-I/AAAAAAAAG-A/6cQNNelsdV0/s1600/body-back.gif
- http://4.bp.blogspot.com/-lWVtT273JDo/T-OZdXNonjI/AAAAAAAAG-I/4VazQayimfI/s1600/header.jpg
- http://1.bp.blogspot.com/-YLR0ecFMGcU/T94oo4nsVQI/AAAAAAAAG6w/yu9ZK1o-n98/s1600/bg_content.gif
- http://4.bp.blogspot.com/-POy-pvgzudE/Tz0SPxJXQnI/AAAAAAAAFUI/SlCAfDMFIhg/s1600/anonymous.jpg
- http://3.bp.blogspot.com/-NONrBLhghFk/To0nNB1LmkI/AAAAAAAAAI4/CAuzDfYiCiU/s1600/comment-arrow.gif
- http://2.bp.blogspot.com/-S4AKqSDPUEs/ToSYCWJy4qI/AAAAAAAAABI/conBgqSajOY/s1600/fade.png
- http://3.bp.blogspot.com/-Qe4UP5Cn9LQ/T3sGU5DTb0I/AAAAAAAAAL8/xJUZ31qQ8B4/s1600/batas.gif
- http://2.bp.blogspot.com/-7BeF7FZiHo0/T6vZzVSzTzI/AAAAAAAABJs/FlrWN7ZRxmk/s1600/drid.gif
- http://1.bp.blogspot.com/-43EW3Gjakwc/T6vZz6K4N_I/AAAAAAAABJ0/hi2LK0zc4JQ/s1600/listed.gif
- http://1.bp.blogspot.com/-cydjTUmm9Bg/T8y2rWHrMKI/AAAAAAAAGmU/EFEdYGPreTU/s1600/body-bg1.png
Embedded domains
- www.w3.org
- www.google.com
- www.blogger.com
- fonts.googleapis.com
- fullpornolariizle.blogspot.com
- 3.bp.blogspot.com
- www.maskolis.com
- 4.bp.blogspot.com
- 1.bp.blogspot.com
- 2.bp.blogspot.com
- ajax.googleapis.com
- this.offset.top-this.margins.top
- po.top
- p.top
- this.offset.click.top
- this.margins.top
- 0-this.offset.relative.top-this.offset.parent.top
- co.top
- this.offset.relative.top-this.offset.parent.top
- pos.top
- this.offset.relative.top
- this.offset.parent.top
- position.top
- style.top
- this.position.top
Embedded IP addresses
- 20.50.201.206
- 57.155.104.224
- 4.230.171.124
- 52.230.60.54
- 74.179.77.204
- 74.179.77.164
- 20.42.65.90
- 4.150.223.104
- 104.18.33.89
- 92.223.78.30
- 13.89.179.12
- 52.110.12.24
- 52.110.12.18
- 72.153.5.96
- 52.148.114.188
- 52.110.12.21
- 52.110.12.31
More Gootloader samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report