SUSPICIOUS — d9f54d09755246ee1e57a12f63cdb41b8e195c9576b8e47dc2190d4cefa86032
SUSPICIOUS — d9f54d09755246ee1e57a12f63cdb41b8e195c9576b8e47dc2190d4cefa86032 is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 50 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
d9f54d09755246ee1e57a12f63cdb41b8e195c9576b8e47dc2190d4cefa86032 - SHA-1:
afe124056776c703426c46637cf9f90a4dfc805d - MD5:
b4b524e010564af7540572db43dd23e0 - ssdeep:
192:VIGGBtJIWsF0+3vNX00wn6Odg+1C9Zhq:VIfIWsK+3vS0wn6OdRcbhq - TLSH:
T1482184049A431EAF52D7D90DA014CABDA0CEE5CF163560D58BCEAB2D54849F5D88A383 - Submitted as: d9f54d09755246ee1e57a12f63cdb41b8e195c9576b8e47dc2190d4cefa86032
- File type: html · Size: 8559 bytes
- Verdict: suspicious (54/100)
Detections (2 of 50 engines)
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
- Microsoft Defender: Trojan:HTML/Faceliker.AP!MTB
MITRE ATT&CK
Why this verdict
The suspicious score of 54/100 is the fusion of 6 weighted signals:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - 1 behavioral detection(s): Possible DNS tunneling (long/many queries) [medium] (rule
tl-dns-tunneling) - dynamic signal, weight 0.40, confidence 0.90 - Embedded network infrastructure: http://www.vvchem.com, http://www.vvchem.com/products/, http://www.vvchem.com/sell/ - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 12 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (12 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
18287 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- tas02.sls.update.microsoft.com
- d.1.d.1.c.4.2.1.4.9.5.2.6.e.8.b.0.0.0.0.0.0.0.0.0.0.0.0.0.8.e.f.ip6.arpa.
- 251.0.0.224.in-addr.arpa.
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- www.msftconnecttest.com
- 85.52.40.23.in-addr.arpa.
- v20.events.data.microsoft.com
- 137.92.232.135.in-addr.arpa.
- ocsp.digicert.com
- settings-win.data.microsoft.com
- 157.37.11.23.in-addr.arpa.
- ctldl.windowsupdate.com
- 161.14.126.40.in-addr.arpa.
- 63.94.165.20.in-addr.arpa.
- v10.events.data.microsoft.com
- 16.4.211.48.in-addr.arpa.
- localhost
- 1.0.0.127.in-addr.arpa.
- 172.138.232.199.in-addr.arpa.
Embedded URLs
- http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd
- http://www.w3.org/1999/xhtml
- http://www.vvchem.com
- http://www.vvchem.com/products/
- http://www.vvchem.com/sell/
- http://www.vvchem.com/buy/
- http://www.vvchem.com/suppliers/
- http://www.vvchem.com/login.jsp
- http://www.vvchem.com/reg.jsp
- https://pagead2.googlesyndication.com/pagead/js/adsbygoogle.js
- http://www.vvchem.com/dictionary/en/
- http://beian.miit.gov.cn
- http://s23.cnzz.com/stat.php?id=3543253&web_id=3543253&show=pic
- https://hm.baidu.com/hm.js?2f78e49beb4702631266e0f0a72433f5
Embedded domains
- www.w3.org
- www.vvchem.com
- pagead2.googlesyndication.com
- beian.miit.gov.cn
- s23.cnzz.com
- hm.baidu.com
- ..localmachine
Embedded IP addresses
- 135.232.92.137
- 20.165.94.63
- 48.211.4.16
- 20.42.73.31
- 52.148.114.188
- 4.247.188.224
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report