SUSPICIOUS — bf705db3376acc0945111b137302187cd5640a2618c8ed537651c4b1debb5c45
SUSPICIOUS — bf705db3376acc0945111b137302187cd5640a2618c8ed537651c4b1debb5c45 is a unknown sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (47/100). 1 of 54 detection engines flagged it.
Identification
- SHA-256:
bf705db3376acc0945111b137302187cd5640a2618c8ed537651c4b1debb5c45 - SHA-1:
c21b0140b545ce2a72a9d5c7722056b94adac5e9 - MD5:
8a2d77a474ca14ddb2bc81d7dc419abc - ssdeep:
96:pDzFt5oCCPe3YbWHThRjenrjHgGoW6hRjenrjHg/YndoY4WLyF:NF/IezTZYRLM - TLSH:
T1F719E823B47AEEBACC5115276CC9802091C25A1F8B54C0C7919E4FDAECBCE916A39069 - Submitted as: bf705db3376acc0945111b137302187cd5640a2618c8ed537651c4b1debb5c45
- File type: unknown · Size: 4276 bytes
- Verdict: suspicious (47/100)
Detections (1 of 54 engines)
- Microsoft Defender: Trojan:HTML/Phish.HNBO!MTB
Why this verdict
The suspicious score of 47/100 is the fusion of 1 weighted signal:
- Microsoft Defender flagged Trojan:HTML/Phish.HNBO!MTB (rule
Trojan:HTML/Phish.HNBO!MTB) - engine signal, weight 0.55, confidence 0.85
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://login.live.com.office.devicemanagement.gemseducation.myshn.net
- https://login.live.com.office.devicemanagement.gemseducation.myshn.net/gls.srf?urlID=WinLiveTermsOfUse&mkt=EN-US
- https://login.live.com.office.devicemanagement.gemseducation.myshn.net/gls.srf?urlID=MSNPrivacyStatement&mkt=EN-US
Embedded domains
- login.live.com.office.devicemanagement.gemseducation.myshn.net
Embedded IP addresses
- 10.23.14.48
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report