MALICIOUS — d3285421298a58d3884d35927618706720926578f9d481d6834ed57208ecd1fd
MALICIOUS — d3285421298a58d3884d35927618706720926578f9d481d6834ed57208ecd1fd is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 3 of 54 detection engines flagged it.
Identification
- SHA-256:
d3285421298a58d3884d35927618706720926578f9d481d6834ed57208ecd1fd - SHA-1:
0c20450fb285e27454ba31935b7c03067288a8eb - MD5:
50d504730cbf340974b617b6a2d28c74 - ssdeep:
768:SWgRfhMJZtrypoEP3Ha/scLjly8kjNfCI5kPjqg1zcqy7qYokLnR0MAEEiwk2+Y:2hqrypoEP3HMM8kjNfC6qYNnJWiwT - TLSH:
T1E331F61F76813D9E4C9495216AAC12D430CF941BA03246EEF1B6DF88E83CC74BD4A85B - Submitted as: d3285421298a58d3884d35927618706720926578f9d481d6834ed57208ecd1fd
- File type: html · Size: 42832 bytes
- Verdict: malicious (99/100)
Detections (3 of 54 engines)
- ClamAV (daily): Html.Exploit.Agent-6598769-0
- Microsoft Defender: TrojanClicker:JS/Faceliker.A
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 99/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Html.Exploit.Agent-6598769-0 (rule
Html.Exploit.Agent-6598769-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged TrojanClicker:JS/Faceliker.A (rule
TrojanClicker:JS/Faceliker.A) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - Obfuscated powershell script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 5 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css, https://bukankeranaakutakcintafull.blogspot.com/favicon.ico, https://bukankeranaakutakcintafull.blogspot.com/feeds/posts/default - static signal, weight 0.35, confidence 0.60
- Extracted generic config (10 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
280 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- desktop-hsgcbep
- login.live.com
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- www.bing.com
- assets.msn.com
- settings-win.data.microsoft.com
- edge.microsoft.com
- time.windows.com
- ctldl.windowsupdate.com
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.google.com/2005/gml/b
- http://www.google.com/2005/gml/data
- http://www.google.com/2005/gml/expr
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css
- https://bukankeranaakutakcintafull.blogspot.com/favicon.ico
- http://bukankeranaakutakcintafull.blogspot.com/2014/01/bukan-kerana-aku-tak-cinta-episod-2.html
- https://bukankeranaakutakcintafull.blogspot.com/feeds/posts/default
- https://bukankeranaakutakcintafull.blogspot.com/feeds/posts/default?alt=rss
- https://www.blogger.com/feeds/4191768082078947788/posts/default
- https://bukankeranaakutakcintafull.blogspot.com/feeds/818591074883918651/comments/default
- http://www.soratemplates.com
- http://bobosh.com
- http://creativecommons.org/licenses/by/3.0
- https://lh6.googleusercontent.com/-JmOMQTpzlaE/UA0OK_ftgZI/AAAAAAAACvI/bK_reeqDTfw/s1600/background-3.jpg
- https://lh3.googleusercontent.com/-g5tVIbtgH-M/UA0OK4pKBbI/AAAAAAAACvM/GpRaXYZfzwU/s140/diamond.png
- https://lh3.googleusercontent.com/-dBy8QTapX9o/UA0OK4O-1dI/AAAAAAAACvE/RyN5nHU2BG8/s20/dropdown.png
- https://lh5.googleusercontent.com/-x8hsq39j8zs/UA0OL5J8P0I/AAAAAAAACvo/azWczQhAAE0/s100/nav-li-ul-li.png
- https://lh3.googleusercontent.com/-7_C5XCVxYeQ/UA0OLuy7l2I/AAAAAAAACvY/VmDWqP3yRSQ/s610/hentry.jpg
- https://lh6.googleusercontent.com/-e5op0nHgRZg/UA0OLooChqI/AAAAAAAACvU/FK_zbJKAo6A/s60/hentry-header.png
- https://lh6.googleusercontent.com/-VmQ1Uwv39L8/UA0OMvX6rdI/AAAAAAAACwI/B0Ps7sWEFek/s400/sprite.png
- https://lh5.googleusercontent.com/-eI_4NIs8Pqg/UA0OLiaVhkI/AAAAAAAACvg/hUf8zqVINfk/s100/hr.png
- https://lh5.googleusercontent.com/-da1j3fLlhRE/UAy_ukci3_I/AAAAAAAACuw/RfL1c6kb5No/s36/author.png
- https://lh4.googleusercontent.com/-vo0kRwWuhsY/UA0OMGMOy0I/AAAAAAAACvw/NVSIMlTags0/s20/newer.png
- https://lh5.googleusercontent.com/-Ck8rPcpjCrc/UA0OMbnSDII/AAAAAAAACv4/o8ulNJo453M/s20/older.png
Embedded domains
- www.w3.org
- www.google.com
- www.blogger.com
- bukankeranaakutakcintafull.blogspot.com
- fonts.googleapis.com
- www.soratemplates.com
- bobosh.com
- creativecommons.org
- lh6.googleusercontent.com
- lh3.googleusercontent.com
- lh5.googleusercontent.com
- lh4.googleusercontent.com
- blogspot.com
- ajax.googleapis.com
- www.facebook.com
- apis.google.com
- pagead2.googlesyndication.com
- www.dailymotion.com
- resources.blogblog.com
- widgets.amung.us
- www.blogblog.com
Embedded IP addresses
- 4.150.223.106
- 20.247.185.124
- 4.230.171.124
- 172.66.2.5
- 40.84.97.4
- 57.154.63.210
- 4.150.223.111
- 72.145.35.109
- 20.184.175.7
- 52.148.114.188
- 52.110.12.11
- 52.110.12.56
File paths
- g:\\
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report