SUSPICIOUS — c56e4f718420820afd6a85d54a5e1aa942a1d86063042ce803083de214d723fd
SUSPICIOUS — c56e4f718420820afd6a85d54a5e1aa942a1d86063042ce803083de214d723fd is a unknown sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (47/100). 1 of 54 detection engines flagged it.
Identification
- SHA-256:
c56e4f718420820afd6a85d54a5e1aa942a1d86063042ce803083de214d723fd - SHA-1:
3e8c20aeabde8451653a895b7c8956a56f455c4c - MD5:
15ce4ee81b2c553c8d948836771cdb0b - ssdeep:
96:pDiaooCCPe3YbWHThRjenrjHgGoW6hRjenrjHg/YndoY4WLyF:E5IezTZYRLM - TLSH:
T19F19E923B47AAEBBCC5115276CC9802091C24A1F4B54C0D7919D5FDBECBCE916B39069 - Submitted as: c56e4f718420820afd6a85d54a5e1aa942a1d86063042ce803083de214d723fd
- File type: unknown · Size: 4277 bytes
- Verdict: suspicious (47/100)
Detections (1 of 54 engines)
- Microsoft Defender: Trojan:HTML/Phish.HNBO!MTB
Why this verdict
The suspicious score of 47/100 is the fusion of 1 weighted signal:
- Microsoft Defender flagged Trojan:HTML/Phish.HNBO!MTB (rule
Trojan:HTML/Phish.HNBO!MTB) - engine signal, weight 0.55, confidence 0.85
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://login.live.com.office.devicemanagement.gemseducation.myshn.net
- https://login.live.com.office.devicemanagement.gemseducation.myshn.net/gls.srf?urlID=WinLiveTermsOfUse&mkt=EN-US
- https://login.live.com.office.devicemanagement.gemseducation.myshn.net/gls.srf?urlID=MSNPrivacyStatement&mkt=EN-US
Embedded domains
- login.live.com.office.devicemanagement.gemseducation.myshn.net
Embedded IP addresses
- 10.23.14.48
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report