MALICIOUS — d32ab44974332375cb7c7ce81e41b86a4e487f2e4d27fb628ac52dddee928ce5
MALICIOUS — d32ab44974332375cb7c7ce81e41b86a4e487f2e4d27fb628ac52dddee928ce5 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the TrojanClicker family. 2 of 54 detection engines flagged it.
Identification
- SHA-256:
d32ab44974332375cb7c7ce81e41b86a4e487f2e4d27fb628ac52dddee928ce5 - SHA-1:
e7b6312f9fb8f5571e41bcbbfdb055ac02b030af - MD5:
21f9163615a94dc8f6e2d349e840227c - ssdeep:
3072:tdjMeRcVhIVs2LQegU0DM0kpUbbF/89rCX7CeBsuFgPESz0ypRkR8QykblPZk4r:9cjJ25RkR8Mr - TLSH:
T1423D6E1B3F4CA9DE04C515A326EC0A9C91DACE9BA06740D4E1B5DF58CC2CE626C7847B - Submitted as: d32ab44974332375cb7c7ce81e41b86a4e487f2e4d27fb628ac52dddee928ce5
- File type: html · Size: 129147 bytes
- Verdict: malicious (92/100) · Family: TrojanClicker
Detections (2 of 54 engines)
- Microsoft Defender: TrojanClicker:JS/Faceliker.N
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 92/100 is the fusion of 7 weighted signals:
- Microsoft Defender flagged TrojanClicker:JS/Faceliker.N (rule
TrojanClicker:JS/Faceliker.N) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec, defense-evasion (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 5 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css, http://limatujuh.blogspot.com/favicon.ico, http://limatujuh.blogspot.com/ - static signal, weight 0.35, confidence 0.60
- Extracted generic config (15 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
280 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- v10.events.data.microsoft.com
- edge.microsoft.com
- time.windows.com
- settings-win.data.microsoft.com
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.google.com/2005/gml/b
- http://www.google.com/2005/gml/data
- http://www.google.com/2005/gml/expr
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css
- http://limatujuh.blogspot.com/favicon.ico
- http://limatujuh.blogspot.com/
- http://limatujuh.blogspot.com/feeds/posts/default
- http://limatujuh.blogspot.com/feeds/posts/default?alt=rss
- https://www.blogger.com/feeds/7719099103408042977/posts/default
- https://www.blogger.com/profile/03165466322039146754
- http://upload.wikimedia.org/wikipedia/commons/thumb/b/b1/US_57.svg/600px-US_57.svg.png
- http://www.premiumbloggertemplates.com/
- http://www.bloggertipandtrick.net/
- http://creativecommons.org/licenses/by/3.0/
- http://ajax.googleapis.com/ajax/libs/mootools/1.2.4/mootools-yui-compressed.js
- http://mootools.net/more
- http://mad4milk.net
- http://www.jondesign.net/
- http://digitarald.de/
- http://4.bp.blogspot.com/_4HKUHirY_2U/TPuGixLvKQI/AAAAAAAAIuY/KbMOX40cGhs/s1600/container-line.png
- http://2.bp.blogspot.com/_4HKUHirY_2U/TPuGi78Z-vI/AAAAAAAAIug/XegCz7y795c/s1600/contetwrap.png
- http://2.bp.blogspot.com/_4HKUHirY_2U/TPuGs-6BkuI/AAAAAAAAIvQ/oXZBn_avxj4/s1600/post-line.png
- http://1.bp.blogspot.com/_4HKUHirY_2U/TPuG9ah-0MI/AAAAAAAAIvo/zEU1B2rowh4/s1600/sidebar_tab.png
- http://2.bp.blogspot.com/_4HKUHirY_2U/TPuGit9qMKI/AAAAAAAAIuQ/dc4O5ztoZoA/s1600/bullet.png
Embedded domains
- www.w3.org
- www.google.com
- www.blogger.com
- limatujuh.blogspot.com
- www.bloggertipandtrick.net
- upload.wikimedia.org
- www.premiumbloggertemplates.com
- creativecommons.org
- ajax.googleapis.com
- mootools.net
- mad4milk.net
- www.jondesign.net
- digitarald.de
- coords.top
- 4.bp.blogspot.com
- 2.bp.blogspot.com
- 1.bp.blogspot.com
- 3.bp.blogspot.com
- p.info
- blogspot.com
- connect.facebook.net
- code.jquery.com
- apis.google.com
- pagead2.googlesyndication.com
- beritakampoeng.blogspot.com
Embedded IP addresses
- 4.150.223.107
- 52.253.84.76
- 4.230.171.124
- 20.50.73.14
- 20.42.179.192
- 72.153.5.136
- 52.148.114.188
- 52.110.12.33
- 52.110.12.21
More TrojanClicker samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report