MALICIOUS — df05cdb875c8c739f4790ded50c1a5a9c6f775bdd704471f725e21582e38c4d3
MALICIOUS — df05cdb875c8c739f4790ded50c1a5a9c6f775bdd704471f725e21582e38c4d3 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (83/100), attributed to the Scrinject family. 1 of 53 detection engines flagged it.
Identification
- SHA-256:
df05cdb875c8c739f4790ded50c1a5a9c6f775bdd704471f725e21582e38c4d3 - SHA-1:
0ea02aafc009bf46e3c1c8da5ca756a2f4f5cca6 - MD5:
55a8abde155a62479499eb9798651a3f - ssdeep:
1536:JnQpp5J5w7bwMa1tqB3RwRnkmquaifSqK25ZOSbo9VZ+phFzgnG:JnovJ50wMamB3RwRnkmqu3fSqK+ZOSkU - TLSH:
T1E63AA81537593EC720E0C91A79480F94E1CA829FF973D1E2D262E7C4E5B8D60AC59CCA - Submitted as: df05cdb875c8c739f4790ded50c1a5a9c6f775bdd704471f725e21582e38c4d3
- File type: html · Size: 93595 bytes
- Verdict: malicious (83/100) · Family: Scrinject
Detections (1 of 53 engines)
- Microsoft Defender: Trojan:HTML/Scrinject.C!bit
Why this verdict
The malicious score of 83/100 is the fusion of 5 weighted signals:
- Memory forensics: 2 finding(s), e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.50, confidence 0.85 - Obfuscated javascript script: dynamic-exec, defense-evasion (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 29 external host(s) at runtime (27 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css, http://iphoneislamicwallpapers.blogspot.com/favicon.ico, http://iphoneislamicwallpapers.blogspot.com/feeds/posts/default - static signal, weight 0.35, confidence 0.60
- Extracted generic config (14 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
278 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- settings-win.data.microsoft.com
Embedded URLs
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css
- http://iphoneislamicwallpapers.blogspot.com/favicon.ico
- http://iphoneislamicwallpapers.blogspot.com/2012/01/please-subscribe-to-our-mailing-list.html
- http://iphoneislamicwallpapers.blogspot.com/feeds/posts/default
- http://iphoneislamicwallpapers.blogspot.com/feeds/posts/default?alt=rss
- https://www.blogger.com/feeds/8398761986252036241/posts/default
- http://iphoneislamicwallpapers.blogspot.com/feeds/720276818385492800/comments/default
- http://fonts.googleapis.com/css?family=Oswald%7C%27+rel%3D%27stylesheet%27+type%3D%27text%2Fcss&ver=3.6.1
- https://ajax.googleapis.com/ajax/libs/jquery/1.5.1/jquery.min.js
- http://fonts.googleapis.com/css?family=Open+Sans:400
- http://googledrive.com/host/0B-UFNCskEl7QZEtoTFcxYVJ0NmM
- http://googledrive.com/host/0B-UFNCskEl7QM2xPUGVleTlELTA
- http://www.templateify.com
- https://ajax.googleapis.com/ajax/libs/jquery/1.8.3/jquery.min.js
- http://ajax.googleapis.com/ajax/libs/jqueryui/1.8.23/jquery-ui.min.js
- https://www.blogger.com/dyn-css/authorization.css?targetBlogID=8398761986252036241&
- http://themeforest.net/item/madidus-blog-magazine-theme/4690753?ref=different-themes
- http://iphoneislamicwallpapers.blogspot.com/
- http://4.bp.blogspot.com/-gUUYCRUUkIY/UjjgdZHYhOI/AAAAAAAABa8/k5Vs4vVx8-w/s1600/Home-48+
- http://schema.org/BlogPosting
- http://3.bp.blogspot.com/-4LNV9IgnYRg/Ujr7crKK_UI/AAAAAAAABdY/FB3BRdVzclI/s1600/user.png
- http://4.bp.blogspot.com/-Zvz7OCzeUEc/Ujr9DwHJ_1I/AAAAAAAABdk/rOv0N5r0XvI/s1600/date.png
- http://4.bp.blogspot.com/-xtxIqXWYuqQ/Ujr9LT4va5I/AAAAAAAABds/mdXWR4KxNhk/s1600/comments.png
- http://iphoneislamicwallpapers.blogspot.com/2012/01/please-subscribe-to-our-mailing-list.html#comment-form
- http://3.bp.blogspot.com/-DydYuQGpSfI/Ujr9LRFmjnI/AAAAAAAABdw/JEo7bFd33NU/s1600/tungs.png
Embedded domains
- www.blogger.com
- iphoneislamicwallpapers.blogspot.com
- fonts.googleapis.com
- ajax.googleapis.com
- googledrive.com
- www.templateify.com
- templateify.com
- blogspot.com
- themeforest.net
- 4.bp.blogspot.com
- schema.org
- 3.bp.blogspot.com
- feedburner.google.com
- sphotos-a-cdg.xx.fbcdn.net
- d.link
- www.gstatic.com
- feeds.feedburner.com
- www.networkedblogs.com
- static.networkedblogs.com
- nwidget.networkedblogs.com
- websitesubmit.hypermart.net
- widgets.amung.us
- islamgreatreligion.blogspot.com
- islam-wallpapers.blogspot.com
- islamgreatreligion.wordpress.com
Embedded IP addresses
- 4.207.44.70
- 52.123.252.193
- 57.154.63.210
- 20.247.185.124
- 4.230.171.124
- 135.233.95.144
- 74.178.240.51
- 20.184.175.11
- 74.178.240.61
- 40.99.133.242
- 40.99.134.2
- 20.76.201.171
- 52.123.128.14
- 52.123.129.14
- 162.159.142.9
- 52.123.252.212
- 135.234.160.246
- 203.26.79.13
- 135.233.95.80
- 52.148.114.188
- 172.178.240.162
- 20.184.175.8
- 20.42.73.30
- 4.209.250.170
- 52.168.117.169
More Scrinject samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report