SUSPICIOUS — c784eeea9a0a5ecb90039885358e4119e68abbda6593743152433e67db81051e
SUSPICIOUS — c784eeea9a0a5ecb90039885358e4119e68abbda6593743152433e67db81051e is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 1 of 53 detection engines flagged it.
Identification
- SHA-256:
c784eeea9a0a5ecb90039885358e4119e68abbda6593743152433e67db81051e - SHA-1:
d267c5674e44bab282105a0bbf558d9de60c2709 - MD5:
f15032f193a484ae1d30ff7bdd1ddcee - ssdeep:
3072:vnWGsPGBEA3PxblKmWjtydX6JaWlKSVmVxGCWLEYAUwnc/+jG1qgiRyp3Xa1ErUd:vnWGsPGBESPxblRU7aWlKUE - TLSH:
T1D64651A0B29DCE8BC1800FF468BC7596A1893A020A147CD51BE5C6DEDEDD731B061DB9 - Submitted as: c784eeea9a0a5ecb90039885358e4119e68abbda6593743152433e67db81051e
- File type: html · Size: 303366 bytes
- Verdict: suspicious (54/100)
Detections (1 of 53 engines)
- Microsoft Defender: Trojan:JS/Redirector.AYLB!MTB
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated powershell script: dynamic-exec, defense-evasion (layers: char-code) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://temp.lowerbeforwarden.ml/temp.js?n=nb5, https://gmpg.org/xfn/11, https://yoast.com/wordpress/plugins/seo/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://temp.lowerbeforwarden.ml/temp.js?n=nb5
- https://gmpg.org/xfn/11
- https://yoast.com/wordpress/plugins/seo/
- https://www.scalestudio.nl/
- https://scalestudio.nl/wp-content/uploads/2020/02/White-version.jpg
- https://schema.org
- https://scalestudio.nl/#organization
- https://scalestudio.nl/
- https://scalestudio.nl/#logo
- https://scalestudio.nl/wp-content/uploads/2020/02/Gruppo.png
- https://scalestudio.nl/#website
- https://www.scalestudio.nl/#primaryimage
- https://www.scalestudio.nl/#webpage
- https://scalestudio.nl/amp/
- https://scalestudio.nl/feed/
- https://scalestudio.nl/comments/feed/
- https://www.monsterinsights.com/
- https://developers.google.com/analytics/devguides/collection/analyticsjs/
- https://scalestudio.nl/wp-content/plugins/jet-menu/integration/themes/astra/assets/css/style.css?ver=2.0.4
- https://scalestudio.nl/wp-content/themes/astra/assets/css/minified/style.min.css?ver=2.4.5
- https://scalestudio.nl/wp-content/themes/astra/assets/fonts/astra.woff
- https://scalestudio.nl/wp-content/themes/astra/assets/fonts/astra.ttf
- https://scalestudio.nl/wp-content/themes/astra/assets/fonts/astra.svg#astra
- https://scalestudio.nl/wp-includes/css/dist/block-library/style.min.css?ver=5.6.6
- https://scalestudio.nl/wp-content/plugins/cookie-law-info/public/css/cookie-law-info-public.css?ver=1.8.8
Embedded domains
- temp.lowerbeforwarden.ml
- gmpg.org
- yoast.com
- www.scalestudio.nl
- scalestudio.nl
- schema.org
- s.w.org
- www.monsterinsights.com
- www.googletagmanager.com
- developers.google.com
- jet-custom-item-label.top
- jet-custom-item-desc.top
- fonts.googleapis.com
- api.w.org
- burodevakmannen.nl
- www.burodevakmannen.nl
- api.whatsapp.com
- www.facebook.com
- www.linkedin.com
- www.instagram.com
- www.w3.org
Embedded IP addresses
- 1.0.76.2
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report