SUSPICIOUS — bb702c9aa3c4ec1a23383954b77e59501c1ed5a006fc990e631db96ff922fa63
SUSPICIOUS — bb702c9aa3c4ec1a23383954b77e59501c1ed5a006fc990e631db96ff922fa63 is a email sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (38/100). 0 of 54 detection engines flagged it.
Identification
- SHA-256:
bb702c9aa3c4ec1a23383954b77e59501c1ed5a006fc990e631db96ff922fa63 - SHA-1:
be6837df4dfb27e830de5d9d1fe75e972466b594 - MD5:
fd8ed897532ca825bf5d6f8023689ad8 - ssdeep:
1536:fjmoHU1zFBkPI6MD8rhOqNkgIAiy9OxuiH4y8kyfGcLMXjVV1kMe+bn+iu16bFWY:fCfPBuIQkQfO8JwcSJeqn+iHFRN - TLSH:
T1B03AF161AD0323A75C490DA497F8416410DD7DF4AEA9D24FAAA5FAF0CC7A0B1531CCA2 - Submitted as: bb702c9aa3c4ec1a23383954b77e59501c1ed5a006fc990e631db96ff922fa63
- File type: email · Size: 101865 bytes
- Verdict: suspicious (38/100)
Detections (0 of 54 engines)
No engine flagged this sample.
Why this verdict
The suspicious score of 38/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: 89.248.99.81 - static signal, weight 0.35, confidence 0.60
- Suspicious email carrier: reply-to-mismatch - static signal, weight 0.30, confidence 0.70
Embedded URLs
- http://www.w3.org/TR/REC-html=
- http://schemas.microsoft.com/office/2004/12/omml
- http://www.w3.org/TR/REC-html40
Embedded domains
- mga.scanner.greenradar.com
- scanner.greenradar.com
- chinahkphoto.com.hk
- grmail.greenradar.com
- billing.anaplaan.com
- hostgbs.vhost.interdominios.com
- unsubscribe.billing.u55f.app.anaplan.comm.com
- billing.u55f.app.anaplan.comm.com
- s.microsoft.com
- www.w3.org
Embedded IP addresses
- 172.17.0.7
- 10.3.128.9
- 89.248.99.81
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report