MALICIOUS — virussign.com_a6bdcdafc183189537a9483acbea87b0.vir
MALICIOUS — virussign.com_a6bdcdafc183189537a9483acbea87b0.vir is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100), attributed to the HTML family. 3 of 51 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d164ed527a68123e02769c10fb4983c8e88a609f4f780e642660f804d159198d - SHA-1:
ed7b3c990360b64075250b9bb657bfeafb08c3e8 - MD5:
a6bdcdafc183189537a9483acbea87b0 - ssdeep:
1536:vIRIOITIwIgIiKZgNDfIwIGI5IVJ7SqIRIOITIwIgIiKZgNDfIwIGI5IVJ7SL1O5:w1O65VA2SMbh3iL - TLSH:
T1814204049D879A8E9087086E96220FC5B14CE91950D6E7DBF0E08D1FCF97354D2AD2EB - Submitted as: virussign.com_a6bdcdafc183189537a9483acbea87b0.vir
- File type: html · Size: 212793 bytes
- Verdict: malicious (95/100) · Family: HTML
Source: VirusSign · first seen 2026-07-17T00:00:00.000Z · SHA-256 verified
Detections (3 of 51 engines)
- Microsoft Defender: Trojan:HTML/Phish.B!atmn
- Emsisoft (Emergency Kit): GT:JS.ObfscRed.2.6C40BC38
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 95/100 is the fusion of 9 weighted signals:
- Memory forensics: 5 finding(s), e.g. RWX/private injected region in taskhostw.exe (pid 7984) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:HTML/Phish.B!atmn (rule
Trojan:HTML/Phish.B!atmn) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged GT:JS.ObfscRed.2.6C40BC38 (rule
GT:JS.ObfscRed.2.6C40BC38) - engine signal, weight 0.55, confidence 0.85 - Obfuscated powershell script: dynamic-exec, defense-evasion (layers: char-code+concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://ogp.me/ns/fb#, https://xttrawave.com/wp-content/uploads/2021/09/TDR-Nova-GE.jpg, https://www.dmgaudio.com/images/products/equality.png - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
281 behavior events · 1 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- desktop-hsgcbep
- edge.microsoft.com
- dns.msftncsi.com
- www.bing.com
- aps.prod.windows.com
- ecs.office.com
- g.live.com
- fs.microsoft.com
- self.events.data.microsoft.com
- www.msftncsi.com
- geo.prod.do.dsp.mp.microsoft.com
- geover.prod.do.dsp.mp.microsoft.com
- watson.events.data.microsoft.com
- 192.168.122.106
- 192.168.122.255
- 224.0.0.252
- 192.168.122.1
- 239.255.255.250
- 192.168.122.105
Dropped files
- efda27a2ef8f58ad8f925e933c925a3929beec63006b00ac7c23217e0838eed6 -
efda27a2ef8f58ad8f925e933c925a3929beec63006b00ac7c23217e0838eed6
Embedded URLs
- http://ogp.me/ns/fb#
- https://xttrawave.com/wp-content/uploads/2021/09/TDR-Nova-GE.jpg
- https://www.dmgaudio.com/images/products/equality.png
- https://i.ytimg.com/vi/q09zvPrSFiA/maxresdefault.jpg
- https://image.slidesharecdn.com/reliabilityandvalidity-100809083558-phpapp02/95/reliability-and-validity-12-728.jpg
- https://image.slidesharecdn.com/validityreliabilityandfeasibility-151104054612-lva1-app6892/95/validity-reliability-and-feasibility-18-638.jpg
- http://image.slidesharecdn.com/assessmentfinal2-131208223610-phpapp01/95/validity-and-reliability-in-assessment-23-638.jpg
- https://i.pinimg.com/originals/e8/0a/d4/e80ad4ccdefa8e207e60bd16bf41468b.jpg
- https://i.ytimg.com/vi/963W4XcI6PI/maxresdefault.jpg
- https://img.p30download.ir/software/screenshot/2017/08/1501670899_capture.png
- https://2.bp.blogspot.com/-GOodtcP5Sxg/VXwo2aksCuI/AAAAAAAAAPw/Ehp2Gfer_LU/s1600/Family-Tree-Maker-Complete-2014-FULLY-Activated.jpg
- https://therealgase.weebly.com/
- https://cdn2.editmysite.com/js/jquery-1.8.3.min.js
- https://www.google.com/recaptcha/api.js
- https://nelosclub.weebly.com/blog/high-tail-hall-full-game-download-free
- https://gasetell.weebly.com/blog/default-windows-7-sp1-xml-autounattend-user-create
- https://therealgase.weebly.com/1/post/2023/08/free-eq-matching-vst.html
- http://twitter.com/share?url=https://therealgase.weebly.com/1/post/2023/08/free-eq-matching-vst.html
- https://ipaddast.weebly.com/blog/claim-discord-nitro-perks-for-warframe-on-steam
- https://therealgase.weebly.com/1/post/2023/08/what-is-the-difference-between-validity-and-reliability.html
- http://twitter.com/share?url=https://therealgase.weebly.com/1/post/2023/08/what-is-the-difference-between-validity-and-reliability.html
- https://marnelo.weebly.com/blog/kung-fu-panda-3-full-movie-in-english-free-download
- https://neloupdate.weebly.com/blog/windows-7-ultimate-sp3-32-64-bit-download-iso
- https://therealgase.weebly.com/1/post/2023/08/family-tree-maker-2014-software-dvd.html
- http://twitter.com/share?url=https://therealgase.weebly.com/1/post/2023/08/family-tree-maker-2014-software-dvd.html
Embedded domains
- ogp.me
- xttrawave.com
- www.dmgaudio.com
- i.ytimg.com
- image.slidesharecdn.com
- i.pinimg.com
- img.p30download.ir
- 2.bp.blogspot.com
- therealgase.weebly.com
- cdn2.editmysite.com
- cdn1.editmysite.com
- www.weebly.com
- www.google.com
- static.zotabox.com
- nelosclub.weebly.com
- gasetell.weebly.com
- twitter.com
- ipaddast.weebly.com
- marnelo.weebly.com
- neloupdate.weebly.com
- blenderartists.org
- res.cloudinary.com
- i.stack.imgur.com
- finalgase.weebly.com
- pizzagase.weebly.com
More HTML samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report