MALICIOUS — d1bcbc5949b50252d9e113cd2324ed11494d3f0f6f4ea26b201d9343a88982a6
MALICIOUS — d1bcbc5949b50252d9e113cd2324ed11494d3f0f6f4ea26b201d9343a88982a6 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (74/100). 0 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d1bcbc5949b50252d9e113cd2324ed11494d3f0f6f4ea26b201d9343a88982a6 - SHA-1:
6e8f920539c32716161eb279c25ba9e9fb857938 - MD5:
376af6851ca47decae035de189ba1efc - ssdeep:
6144:EipsY0HwbxDoNvoN0okHw4eLevJMC3jT:EVPHwbxDoNvoN0reLejT - TLSH:
T1AD4694D9E56B197F6440207395A808980CEFBF7AB43387A493EE7E408D26933C5BD416 - Submitted as: d1bcbc5949b50252d9e113cd2324ed11494d3f0f6f4ea26b201d9343a88982a6
- File type: html · Size: 296188 bytes
- Verdict: malicious (74/100)
Detections (0 of 54 engines)
No engine flagged this sample.
MITRE ATT&CK
Why this verdict
The malicious score of 74/100 is the fusion of 6 weighted signals:
- Obfuscated javascript script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 20 external host(s) and 12 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/2326567743-css_bundle_v2_rtl.css, http://yosbooks.blogspot.com/favicon.ico, http://yosbooks.blogspot.com/ - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (13 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
16696 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- tas02.sls.update.microsoft.com
- v10.events.data.microsoft.com
- 76.0.240.10.in-addr.arpa.
- 1.0.240.10.in-addr.arpa.
- d.1.d.1.c.4.2.1.4.9.5.2.6.e.8.b.0.0.0.0.0.0.0.0.0.0.0.0.0.8.e.f.ip6.arpa.
- 251.0.0.224.in-addr.arpa.
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 252.0.0.224.in-addr.arpa.
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 164.14.126.40.in-addr.arpa.
- settings-win.data.microsoft.com
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.google.com/2005/gml/b
- http://www.google.com/2005/gml/data
- http://www.google.com/2005/gml/expr
- https://www.blogger.com/static/v1/widgets/2326567743-css_bundle_v2_rtl.css
- http://yosbooks.blogspot.com/favicon.ico
- http://yosbooks.blogspot.com/
- http://yosbooks.blogspot.com/feeds/posts/default
- http://yosbooks.blogspot.com/feeds/posts/default?alt=rss
- https://www.blogger.com/feeds/7565409488193489193/posts/default
- https://www.blogger.com/profile/10009108960562515074
- https://www.blogger.com/static/v1/jsbin/403901366-ieretrofit.js
- http://fonts.googleapis.com/css?family=Tajawal:400
- https://fonts.googleapis.com/css?family=Lemonada
- https://maxcdn.bootstrapcdn.com/font-awesome/4.5.0/css/font-awesome.min.css
- http://www.soratemplates.com
- http://sam-wb.blogspot.com/
- http://1.bp.blogspot.com/-siy6EKYCLtM/U6X4AdKrr0I/AAAAAAAANDs/HCjRvuedDro/s1600/openquote1.gif
- http://3.bp.blogspot.com/-UjppXQI-ww0/U6X4IpheNiI/AAAAAAAAND0/PJhRvvhAWGU/s1600/closequote1.gif
- https://2.bp.blogspot.com/-885osCcs6CA/V8kwiiRItZI/AAAAAAAAA1Q/ej5g-D7Y74MXTcLqJOWA5FGMbjFHbFJXwCLcB/s1600/hourglass.gif
- http://2.bp.blogspot.com/-ReAMfeZ3V68/Vs8X1mFeG6I/AAAAAAAADHU/0uaR6bxj7hU/s1600-r/bg2.png
- https://images.pexels.com/photos/590493/pexels-photo-590493.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940
- http://2.bp.blogspot.com/-_IyTmlpHtg8/Vmi5pkn5ZAI/AAAAAAAACVI/G4Kylbm3CDo/s1600-r/gradient.png
- http://3.bp.blogspot.com/-LnvazGBvKh8/VskckSkmzxI/AAAAAAAAC4s/erEgI6A_ih4/s1600-r/metabg.png
- https://4.bp.blogspot.com/-OeDHvvNC6FY/V8f8bxqEtyI/AAAAAAAAA00/lJW9aFRzLTY3iZ7AGQUvBoOa53cldSYYwCLcB/s1600/bg-subcribe.png
Embedded domains
- www.w3.org
- www.google.com
- www.blogger.com
- yosbooks.blogspot.com
- fonts.googleapis.com
- maxcdn.bootstrapcdn.com
- ajax.googleapis.com
- www.soratemplates.com
- sam-wb.blogspot.com
- 1.bp.blogspot.com
- 3.bp.blogspot.com
- 2.bp.blogspot.com
- images.pexels.com
- 4.bp.blogspot.com
- rating-widget.com
- entry.link
- blogspot.com
- schema.org
- pagead2.googlesyndication.com
- uprimp.com
- yllix.com
- ylx-aff.advertica-cdn.com
- resources.blogblog.com
- i.ytimg.com
- vid.alarabiya.net
Embedded IP addresses
- 57.154.63.210
- 74.178.76.128
- 20.42.179.192
- 172.172.255.216
- 4.150.223.105
- 20.89.1.8
- 40.84.85.40
- 85.210.193.152
- 20.165.94.63
- 72.145.35.97
- 4.207.44.73
- 48.211.4.16
- 52.123.252.248
- 203.26.79.13
- 4.150.223.112
- 92.223.78.30
- 20.42.73.25
- 85.210.196.11
- 20.42.179.204
- 57.155.104.224
- 40.79.163.155
- 4.150.223.101
- 52.148.114.188
- 20.42.73.27
- 4.247.188.233
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report