SUSPICIOUS — bb2ae3799510ca93c722c34c1c202da1c336b755b1df87fc800ef041f1412ba9
SUSPICIOUS — bb2ae3799510ca93c722c34c1c202da1c336b755b1df87fc800ef041f1412ba9 is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
bb2ae3799510ca93c722c34c1c202da1c336b755b1df87fc800ef041f1412ba9 - SHA-1:
350c6bb2c4da4b5d039d8dbb4950f458a47e6736 - MD5:
a6ab2c5f81e388af92cb8960b49d7aa1 - ssdeep:
3072:1YKpqoeCQ2ohVQC/UcjvG8rMUnYnT01KRdVvofv6M/hpc:1tqoeCQ2ohVQCNCTv - TLSH:
T1503B292B32717D8F04F8551368DD4B9570DA8A6FAC2641E5E1E6BB88EC38C306D8C45E - Submitted as: bb2ae3799510ca93c722c34c1c202da1c336b755b1df87fc800ef041f1412ba9
- File type: html · Size: 112150 bytes
- Verdict: suspicious (54/100)
Detections (2 of 50 engines)
- Microsoft Defender: flagged
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css, http://fonts.googleapis.com/css?family=Marvel, http://fonts.googleapis.com/css?family=Play - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.google.com/2005/gml/b
- http://www.google.com/2005/gml/data
- http://www.google.com/2005/gml/expr
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css
- https://plus.google.com/111325999121541719168
- http://fonts.googleapis.com/css?family=Marvel
- http://fonts.googleapis.com/css?family=Play
- http://fonts.googleapis.com/css?family=Lobster
- http://fonts.googleapis.com/css?family=Shadows+Into+Light
- http://fonts.googleapis.com/css?family=Droid+Sans:bold
- http://fonts.googleapis.com/css?family=Droid+Serif:bold
- http://fonts.googleapis.com/css?family=Raleway:100
- http://muhammadfarhad.blogspot.com/favicon.ico
- http://muhammadfarhad.blogspot.com/
- http://muhammadfarhad.blogspot.com/feeds/posts/default
- http://muhammadfarhad.blogspot.com/feeds/posts/default?alt=rss
- https://www.blogger.com/feeds/5941532328144227144/posts/default
- https://www.blogger.com/profile/10638648411250766617
- http://creativecommons.org/licenses/by/3.0
- http://4.bp.blogspot.com/-r-E8kGz7i9E/T9pY-QF2UFI/AAAAAAAADP4/MM8JIOqS5x8/s1600/h2.jpg
- http://1.bp.blogspot.com/-3lNtLBgMe24/TymBqycue0I/AAAAAAAAC8U/g5MEdEJoWVU/s1600/post.png
- https://lh4.googleusercontent.com/-lQcSHIMHmvg/UPbM703qX1I/AAAAAAAAFTc/ZP9KWt2Hgv0/h120/muhammadfarhad-blockquote.JPG
- http://2.bp.blogspot.com/-MukJE3TVH4U/ThlGuAuWhhI/AAAAAAAAAYs/un2cfPTJyjM/s1600/postcont.png
- http://2.bp.blogspot.com/-aMX6hSCdRP0/T9pdo2RGdOI/AAAAAAAADQs/gxQKqa9k_U4/s1600/low.jpg
Embedded domains
- www.w3.org
- www.google.com
- www.blogger.com
- plus.google.com
- fonts.googleapis.com
- muhammadfarhad.blogspot.com
- www.deluxetemplates.net
- creativecommons.org
- 4.bp.blogspot.com
- 1.bp.blogspot.com
- lh4.googleusercontent.com
- 2.bp.blogspot.com
- 3.bp.blogspot.com
- themes.googleusercontent.com
- ajax.googleapis.com
- www.opensource.org
- www.gnu.org
- users.tpg.com.au
- jquery.malsup.com
- malsup.com
- code.jquery.com
- blogspot.com
- schema.org
- nexmo.com
- gmail.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report