MALICIOUS — df0f6fcd2e5a2980aa8409931b33b814c8e551d794412a1060270b4c5e2951f2
MALICIOUS — df0f6fcd2e5a2980aa8409931b33b814c8e551d794412a1060270b4c5e2951f2 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
df0f6fcd2e5a2980aa8409931b33b814c8e551d794412a1060270b4c5e2951f2 - SHA-1:
ecc45c98167c916c8bd42cb8518e936030921359 - MD5:
12c5b9066607dc825fa548b3b94cf7d5 - ssdeep:
768:XbOsnQCpxZnXnTP+HT8Gj+55cKVawLbcmbdsv1iwQVwxNntugy0Mapw3oDCMEp/b:XSCpxZXTP+H1+Da9mbdsv1iwQVwxNntu - TLSH:
T1852D941B3651398158E10A0BD1DC48F8D49AD1AB877F86F5C7ABD684A42ACB08C9F427 - Submitted as: df0f6fcd2e5a2980aa8409931b33b814c8e551d794412a1060270b4c5e2951f2
- File type: html · Size: 28651 bytes
- Verdict: malicious (96/100)
Detections (2 of 53 engines)
- ClamAV (daily): Win.Trojan.Crypt-291
- Microsoft Defender: Trojan:HTML/Cryxos.PA!MTB
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Crypt-291 (rule
Win.Trojan.Crypt-291) - engine signal, weight 0.90, confidence 0.95 - Obfuscated javascript script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 30 external host(s) at runtime (28 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://gmpg.org/xfn/11, http://www.loadnangr.com/wp-content/themes/lightword/favicon.ico, http://www.loadnangr.com/xmlrpc.php - static signal, weight 0.35, confidence 0.60
- Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
277 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- settings-win.data.microsoft.com
- www.msn.com
Embedded URLs
- http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd
- http://www.w3.org/1999/xhtml
- http://gmpg.org/xfn/11
- http://www.loadnangr.com/wp-content/themes/lightword/favicon.ico
- http://www.loadnangr.com/xmlrpc.php
- http://www.loadnangr.com/index.php/feed/
- http://www.loadnangr.com/index.php/comments/feed/
- http://www.loadnangr.com/index.php/722/kho-rak-ik-krang/feed/
- http://www.loadnangr.com/wp-content/themes/lightword/style.css
- http://www.loadnangr.com/wp-content/themes/lightword/wider.css
- http://www.loadnangr.com/wp-content/plugins/wp-google-search/wgs.css?ver=5.1.11
- http://www.loadnangr.com/wp-content/plugins/wp-google-search/wgs2.css?ver=5.1.11
- http://www.loadnangr.com/wp-includes/css/dist/block-library/style.min.css?ver=5.1.11
- http://www.loadnangr.com/wp-includes/js/jquery/jquery.js?ver=1.12.4
- http://www.loadnangr.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.4.1
- http://www.loadnangr.com/wp-content/plugins/google-analyticator/external-tracking.min.js?ver=6.5.4
- https://api.w.org/
- http://www.loadnangr.com/index.php/wp-json/
- http://www.loadnangr.com/xmlrpc.php?rsd
- http://www.loadnangr.com/wp-includes/wlwmanifest.xml
- http://www.loadnangr.com/index.php/720/khang-hod-daen-thuan/
- http://www.loadnangr.com/index.php/724/motorcycle-pha-siaw/
- http://www.loadnangr.com/index.php/722/kho-rak-ik-krang/
- http://www.loadnangr.com/?p=722
- http://www.loadnangr.com/index.php/wp-json/oembed/1.0/embed?url=http%3A%2F%2Fwww.loadnangr.com%2Findex.php%2F722%2Fkho-rak-ik-krang%2F
Embedded domains
- www.w3.org
- gmpg.org
- www.loadnangr.com
- s.w.org
- api.w.org
- loadnangr.com
- d.plugrush.com
- www.videousermanuals.com
- google-analytics.com
- videobam.com
- f.3ezy.net
- www.ethaicd.com
- www.zff.co
- t6.imgchili.net
- www.plugrush.com
- ryushare.com
- i1216.photobucket.com
- www.yyv.co
- www.bigfile.to
- www.filefactory.com
- adf.ly
- www.megashares.com
- depositfiles.com
- www.linkbucks.com
- www.share-online.biz
Embedded IP addresses
- 4.207.44.70
- 52.123.252.227
- 48.211.4.16
- 4.230.171.124
- 20.247.185.124
- 74.178.240.61
- 20.184.175.11
- 74.178.240.51
- 20.42.65.88
- 4.247.188.233
- 20.76.201.171
- 52.123.128.14
- 40.103.64.242
- 52.123.129.14
- 4.247.188.224
- 52.123.252.223
- 135.234.160.246
- 203.26.79.13
- 135.233.95.80
- 52.123.252.233
- 52.148.114.188
- 172.66.2.5
- 20.42.65.93
- 4.150.223.100
- 48.192.143.121
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report