MALICIOUS — d3271d526831d4629b35d968049c48274acc4c153ecba876075b1576c86aa9f5
MALICIOUS — d3271d526831d4629b35d968049c48274acc4c153ecba876075b1576c86aa9f5 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the HideLink family. 3 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d3271d526831d4629b35d968049c48274acc4c153ecba876075b1576c86aa9f5 - SHA-1:
07754fe466b06178aea821a1e5cffa0716f17b9c - MD5:
094fb4c272dfeba68bfdd7bfc272b32a - ssdeep:
1536:XLNCyjuTalxND1lxcQ2pfLs4jV8/4h9VnqUQNl7MvPL/P:pCyjuTalxl1lxcQ2pfLs4jV4S1aloLP - TLSH:
T14B357515A71A3EDF00DCC003D1CC45ADC0FA6AEF992661EFCA949BEA641CD50AC0975B - Submitted as: d3271d526831d4629b35d968049c48274acc4c153ecba876075b1576c86aa9f5
- File type: html · Size: 62960 bytes
- Verdict: malicious (99/100) · Family: HideLink
Detections (3 of 54 engines)
- ClamAV (daily): Js.Trojan.Obfus-633
- Microsoft Defender: Trojan:JS/HideLink.A
- Kaspersky (KVRT): Trojan-Downloader.JS.Agent.hbs
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Js.Trojan.Obfus-633 (rule
Js.Trojan.Obfus-633) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:JS/HideLink.A (rule
Trojan:JS/HideLink.A) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan-Downloader.JS.Agent.hbs (rule
Trojan-Downloader.JS.Agent.hbs) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 27 external host(s) and 14 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://gmpg.org/xfn/11, https://buildingfailures.com/wp-content/themes/spectrum/style.css, https://buildingfailures.com/wp-content/themes/spectrum/css/effects.css - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 4 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
13524 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 252.0.0.224.in-addr.arpa.
- 85.52.40.23.in-addr.arpa.
- nexusrules.officeapps.live.com
- 150.109.171.150.in-addr.arpa.
- desktop-hsgcbep
- update.googleapis.com
- self.events.data.microsoft.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 14.207.250.142.in-addr.arpa
- 251.0.0.224.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 1.0.240.10.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
Embedded URLs
- http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd
- http://www.w3.org/1999/xhtml
- http://gmpg.org/xfn/11
- https://buildingfailures.com/wp-content/themes/spectrum/style.css
- https://buildingfailures.com/wp-content/themes/spectrum/css/effects.css
- https://buildingfailures.com/feed/
- https://buildingfailures.com/xmlrpc.php
- https://buildingfailures.com/tag/failures-news/feed/
- https://buildingfailures.com/wp-includes/css/dist/block-library/style.min.css?ver=5.8.1
- https://buildingfailures.com/wp-includes/js/jquery/jquery.min.js?ver=3.6.0
- https://buildingfailures.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.3.2
- https://buildingfailures.com/wp-content/themes/spectrum/includes/js/superfish.js?ver=5.8.1
- https://buildingfailures.com/wp-content/themes/spectrum/includes/js/woo_tabs.js?ver=5.8.1
- https://buildingfailures.com/wp-content/themes/spectrum/includes/js/general.js?ver=5.8.1
- https://buildingfailures.com/wp-content/themes/spectrum/includes/js/loopedSlider.js?ver=5.8.1
- https://api.w.org/
- https://buildingfailures.com/wp-json/
- https://buildingfailures.com/wp-json/wp/v2/tags/45
- https://buildingfailures.com/xmlrpc.php?rsd
- https://buildingfailures.com/wp-includes/wlwmanifest.xml
- https://buildingfailures.com/wp-content/themes/spectrum/styles/blue_minimal.css
- https://buildingfailures.com/wp-content/themes/spectrum/functions/css/shortcodes.css
- https://buildingfailures.com/wp-content/themes/spectrum/custom.css
- https://buildingfailures.com/wp-content/themes/spectrum/includes/js/pngfix.js
- https://buildingfailures.com/wp-content/themes/spectrum/includes/js/menu.js
Embedded domains
- www.w3.org
- gmpg.org
- buildingfailures.com
- s.w.org
- api.w.org
- twitter.com
- www.asce.org
- hazards.atcouncil.org
- www.claimsjournal.com
- www.constructionhistorysociety.org
- www.structural-safety.org
- www.disastersafety.org
- www.eeri.org
- epicdisasters.com
- www.nist.gov
- failures.wikispaces.com
- www.fema.gov
- www3.gendisasters.com
- www.greenbuildingadvisor.com
- www.historypin.com
- www.iris.edu
- ascelibrary.org
- www.nibs.org
- www.colorado.edu
- www.osha.gov
Embedded IP addresses
- 20.42.73.26
- 20.89.1.11
- 4.150.223.105
- 172.215.188.225
- 72.154.7.103
- 40.79.167.10
- 20.42.73.25
- 72.145.35.97
- 52.148.114.188
- 51.105.71.136
- 4.207.44.73
- 20.42.179.204
- 52.110.12.2
- 172.172.255.217
- 4.150.223.96
- 172.66.2.5
- 48.211.4.16
- 4.150.223.104
- 13.69.109.131
- 135.232.92.34
- 4.247.188.233
- 72.145.35.96
- 203.26.79.13
- 51.132.193.104
- 20.42.73.28
More HideLink samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report