SUSPICIOUS — gzBM75[1].htm
SUSPICIOUS — gzBM75[1].htm is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 0 of 53 detection engines flagged it.
Identification
- SHA-256:
cace7b1fe2eca55aa3fe44fc13cd5e75bc75d8fe0b80cc5a84df8e66eabc7499 - SHA-1:
ea59e66da2778e9abab9474ad23c56ace4e7c06c - MD5:
b0836c34b7e5e2a6d221f58546fd3575 - ssdeep:
48:PmcVh2Wx4GKdyfJdiZNKvanHMX/q4Oxf6qKcsP/j:PmI2Wx4k6T0q7f6qSr - TLSH:
T1DD15B76CB2102F9FCB681019F9EC805C50C9E0DBE6304EB0410E9F8C9C05DE4E579197 - Submitted as: gzBM75[1].htm
- File type: html · Size: 2569 bytes
- Verdict: suspicious (54/100)
Detections (0 of 53 engines)
No engine flagged this sample.
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://fonts.googleapis.com/css?family=Roboto:400, https://www.googletagmanager.com/gtag/js?id=G-ZJL2SP8J7Z, https://s.click.aliexpress.com/e/_DCn9agN?bz=300*250 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://fonts.googleapis.com/css?family=Roboto:400
- https://www.googletagmanager.com/gtag/js?id=G-ZJL2SP8J7Z
- https://www.w3.org/2000/svg
- https://s.click.aliexpress.com/e/_DCn9agN?bz=300*250
- https://ae01.alicdn.com/kf/S3619e57974f148d087c950fe497cdf55q/300x250.jpg
- https://static.cloudflareinsights.com/beacon.min.js/v4513226cdae34746b4dedf0b4dfa099e1781791509496
Embedded domains
- fonts.googleapis.com
- www.googletagmanager.com
- www.w3.org
- s.click.aliexpress.com
- ae01.alicdn.com
- static.cloudflareinsights.com
Embedded IP addresses
- 3.3.9.3
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report