MALICIOUS — b6edb20ee7343e42247cff7f4e75e0343c84ab4591af925a3c6c8344e5f5271b
MALICIOUS — b6edb20ee7343e42247cff7f4e75e0343c84ab4591af925a3c6c8344e5f5271b is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the TrojanClicker family. 2 of 54 detection engines flagged it.
Identification
- SHA-256:
b6edb20ee7343e42247cff7f4e75e0343c84ab4591af925a3c6c8344e5f5271b - SHA-1:
dae1c83db1976d7bf378436a290973ce850166d9 - MD5:
c963201fc85d3a3df4ec4536b2aa7c4b - ssdeep:
3072:P1yVz1WgAUggerBPYjGG9lE/sMEmBZgb1V75HbR2:pYXXFj75HbQ - TLSH:
T19B3DD82F3B557D465490A15676AC3E8C91D2832AF93384FAF033B6848928C74ED4EC17 - Submitted as: b6edb20ee7343e42247cff7f4e75e0343c84ab4591af925a3c6c8344e5f5271b
- File type: html · Size: 126045 bytes
- Verdict: malicious (92/100) · Family: TrojanClicker
Detections (2 of 54 engines)
- Microsoft Defender: TrojanClicker:JS/Faceliker.M
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 92/100 is the fusion of 7 weighted signals:
- Microsoft Defender flagged TrojanClicker:JS/Faceliker.M (rule
TrojanClicker:JS/Faceliker.M) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 16 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css, http://freecodeshare.blogspot.com/favicon.ico, http://freecodeshare.blogspot.com/search/label/SAO - static signal, weight 0.35, confidence 0.60
- Extracted generic config (8 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
281 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- www.bing.com
- settings-win.data.microsoft.com
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.google.com/2005/gml/b
- http://www.google.com/2005/gml/data
- http://www.google.com/2005/gml/expr
- https://www.facebook.com/2008/fbml
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css
- http://freecodeshare.blogspot.com/favicon.ico
- http://freecodeshare.blogspot.com/search/label/SAO
- http://freecodeshare.blogspot.com/feeds/posts/default
- http://freecodeshare.blogspot.com/feeds/posts/default?alt=rss
- https://www.blogger.com/feeds/4303548154641744104/posts/default
- https://www.blogger.com/profile/08817843000594979451
- http://share123.vn
- https://lh6.googleusercontent.com/-_4kZHLjqO6A/ULGjxN4gGLI/AAAAAAAAKCs/BzXRCu1enaE/s369/bg-body.gif
- https://lh5.googleusercontent.com/-V6xvhwsqsG4/T7cHn8ByR5I/AAAAAAAAJg4/imuiQq8PMbA/s40/Icon_Quote.png
- https://lh6.googleusercontent.com/-j1NI0_WrRkw/T40ylNRk6nI/AAAAAAAAJKI/9O-JgaIV6EQ/s16/rss_alt_16x16.png
- https://lh3.googleusercontent.com/-Xla9rTS02Fk/T40ylpqblSI/AAAAAAAAJKQ/lrZW0zK6P_Q/s16/user_12x16.png
- https://lh3.googleusercontent.com/-Eykx0WAEb5s/T40ykWBI9ZI/AAAAAAAAJJ8/RCI6gP0CLLE/s16/clock_16x16.png
- https://lh5.googleusercontent.com/-86PFRyHe9As/T40ykYuiLZI/AAAAAAAAJKA/Yj8luErnfqI/s16/comment_alt1_stroke_16x12.png
- https://lh5.googleusercontent.com/-KexZaDYhr7I/T40ylY1OYCI/AAAAAAAAJKU/bfYTe2-C70c/s16/tag_fill_16x16.png
- http://lh6.ggpht.com/-GDMurKK2tec/T5JCD6hoKoI/AAAAAAAABAc/COHOItBlFWk/author.png
- https://lh5.googleusercontent.com/-j4sA50AKFhw/ULhcCvbSX3I/AAAAAAAAKEw/2KyrIDJyFmc/s210/left.png
- https://lh6.googleusercontent.com/-UeiVpMnAE40/ULhcCtvn4tI/AAAAAAAAKEs/P1LrOch5M9o/s210/left-hover.png
- https://lh5.googleusercontent.com/-1KKaGeacsXM/ULhcDQE7cCI/AAAAAAAAKE4/U18lhJaeDTM/s210/right.png
- https://lh4.googleusercontent.com/-o4YPaBDHpN4/ULhcCi7pWfI/AAAAAAAAKE0/o96Dm00cJlQ/s210/right-hover.png
Embedded domains
- www.w3.org
- www.google.com
- www.facebook.com
- www.blogger.com
- freecodeshare.blogspot.com
- lh6.googleusercontent.com
- lh5.googleusercontent.com
- lh3.googleusercontent.com
- lh6.ggpht.com
- lh4.googleusercontent.com
- 1.bp.blogspot.com
- 3.bp.blogspot.com
- www.techprevue.com
- ajax.googleapis.com
- tintuctv.googlecode.com
- blogspot.com
- apis.google.com
- pagead2.googlesyndication.com
- icons.iconarchive.com
- iloveicons.ru
- cdn3.iconfinder.com
- cdn4.iconfinder.com
- 4.bp.blogspot.com
- demooaxe.blogspot.com
- schema.org
Embedded IP addresses
- 51.132.193.105
- 4.230.171.124
- 85.210.196.11
- 52.230.60.54
- 74.179.77.204
- 104.18.33.89
- 74.178.240.51
- 52.168.117.174
- 74.178.76.128
- 72.153.5.136
- 52.148.114.188
- 52.110.12.46
- 52.110.12.22
More TrojanClicker samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report