MALICIOUS — d3288f07e5616ccd1f8c419736b5ef8db4a39e80061810f7f1c1178bf3309b16
MALICIOUS — d3288f07e5616ccd1f8c419736b5ef8db4a39e80061810f7f1c1178bf3309b16 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (91/100). 2 of 54 detection engines flagged it.
Identification
- SHA-256:
d3288f07e5616ccd1f8c419736b5ef8db4a39e80061810f7f1c1178bf3309b16 - SHA-1:
223a236ab1fa9bd3b3170cf777d661ab113b1b68 - MD5:
2fd9ca729ac8cf42d2ee9e6682913c31 - ssdeep:
1536:SXNsKNWlJ9YNVu8T+rsigAFfF8mZE6q7qUcH8VNHeVPemeVeU0eiRtA8IOxL:+sKNWlCVid4kcVmAOxL - TLSH:
T18541A6627E8C369180E41C00E9CC63B7949A6E5A641038DD91E9EFAFEC1CF73847156E - Submitted as: d3288f07e5616ccd1f8c419736b5ef8db4a39e80061810f7f1c1178bf3309b16
- File type: html · Size: 183703 bytes
- Verdict: malicious (91/100)
Detections (2 of 54 engines)
- Microsoft Defender: Trojan:JS/Redirector!rfn
- Emsisoft (Emergency Kit): Trojan.HTML.ScrInject.5
Why this verdict
The malicious score of 91/100 is the fusion of 6 weighted signals:
- Microsoft Defender flagged Trojan:JS/Redirector!rfn (rule
Trojan:JS/Redirector!rfn) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.HTML.ScrInject.5 (rule
Trojan.HTML.ScrInject.5) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec, defense-evasion (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://ogp.me/ns#, http://ogp.me/ns/fb#, http://inveroart.com/feed/ - static signal, weight 0.35, confidence 0.60
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
288 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- edge.microsoft.com
- time.windows.com
- settings-win.data.microsoft.com
- geo.prod.do.dsp.mp.microsoft.com
Embedded URLs
- http://ogp.me/ns#
- http://ogp.me/ns/fb#
- http://inveroart.com/feed/
- http://inveroart.com/documenta-14-an-art-event-to-feed-the-intellect/
- http://inveroart.com/wp-content/uploads/2017/07/Jannis-Kounellis1.jpg
- http://inveroart.com/wp-includes/css/dist/block-library/style.min.css?ver=5.8.1
- http://inveroart.com/wp-content/plugins/meteor-slides/css/meteor-slides.css?ver=1.0
- http://inveroart.com/wp-content/themes/Avada/assets/css/style.min.css?ver=5.0.1
- http://inveroart.com/wp-content/themes/Avada/shortcodes.css?ver=5.0.1
- http://inveroart.com/wp-content/themes/Avada/assets/fonts/fontawesome/font-awesome.css?ver=5.0.1
- http://inveroart.com/wp-content/themes/Avada/assets/css/ie8.css?ver=5.0.1
- http://inveroart.com/wp-content/themes/Avada/assets/css/ie.css?ver=5.0.1
- http://inveroart.com/wp-content/themes/Avada/ilightbox.css?ver=5.0.1
- http://inveroart.com/wp-content/themes/Avada/animations.css?ver=5.0.1
- http://inveroart.com/wp-content/plugins/woodojo/bundled/woodojo-social-widgets/assets/css/style.css?ver=5.8.1
- http://inveroart.com/wp-includes/css/dashicons.min.css?ver=5.8.1
- http://inveroart.com/wp-includes/js/thickbox/thickbox.css?ver=5.8.1
- http://inveroart.com/wp-content/plugins/woodojo/bundled/woodojo-tabs/assets/css/style.css?ver=5.8.1
- http://inveroart.com/wp-content/plugins/fusion-builder/css/fusion-shortcodes.css?ver=1.0.1
- https://fonts.googleapis.com/css?family=PT+Sans%3Aregular%2C700%7CRoboto+Slab%3A300&
- http://inveroart.com/wp-includes/js/jquery/jquery.min.js?ver=3.6.0
- http://inveroart.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.3.2
- http://inveroart.com/wp-content/plugins/meteor-slides/js/jquery.cycle.all.js?ver=5.8.1
- http://inveroart.com/wp-content/plugins/meteor-slides/js/jquery.metadata.v2.js?ver=5.8.1
- http://inveroart.com/wp-content/plugins/meteor-slides/js/jquery.touchwipe.1.1.1.js?ver=5.8.1
Embedded domains
- ogp.me
- fonts.googleapis.com
- s.w.org
- inveroart.com
- api.w.org
- google-analytics.com
- link-type-button-bar.link
- theme-fusion.com
- data-vocabulary.org
Embedded IP addresses
- 20.42.65.94
- 52.253.84.76
- 52.123.252.194
- 4.230.171.124
- 48.211.4.16
- 52.148.114.188
- 52.110.12.30
- 72.145.35.104
- 52.110.12.49
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report