SUSPICIOUS — e0d94f55cd28a11f4a0ec27537b291a1f87f98a8cf5a6e1d509e13850a41acc9
SUSPICIOUS — e0d94f55cd28a11f4a0ec27537b291a1f87f98a8cf5a6e1d509e13850a41acc9 is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
e0d94f55cd28a11f4a0ec27537b291a1f87f98a8cf5a6e1d509e13850a41acc9 - SHA-1:
0d413629d984642ddb9cb7c546f12b3fd7bf8b0e - MD5:
a2246f8a50049b0ca719ae77551b6680 - ssdeep:
384:VfRIjUDGO2G9kLL9jl+dVchXYeCrthPziMKxvEO1dCjgv/ZWrFV:VfRIjUDGO2G9kLL9jl+dVc7yLKx3dCAU - TLSH:
T19928A70FC673A7EF4C814492A691F46AFCE4B8FA57FD98F6CA48460A6400D6074973C6 - Submitted as: e0d94f55cd28a11f4a0ec27537b291a1f87f98a8cf5a6e1d509e13850a41acc9
- File type: html · Size: 18125 bytes
- Verdict: suspicious (54/100)
Detections (2 of 53 engines)
- Microsoft Defender: TrojanDownloader:HTML/ScrInject.PD!MTB
- Emsisoft (Emergency Kit): Generic.HTML.Phishing.AV.51D1C140
Why this verdict
The suspicious score of 54/100 is the fusion of 4 weighted signals:
- Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 26 external host(s) at runtime (27 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://ajax.googleapis.com/ajax/libs/jquery/1.11.1/jquery.min.js, https://oss.maxcdn.com/html5shiv/3.7.2/html5shiv.min.js, https://oss.maxcdn.com/respond/1.4.2/respond.min.js - static signal, weight 0.35, confidence 0.60
- Extracted generic config (16 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
279 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- msedge.api.cdp.microsoft.com
- oneocsp.microsoft.com
- www.msn.com
Embedded URLs
- https://ajax.googleapis.com/ajax/libs/jquery/1.11.1/jquery.min.js
- https://oss.maxcdn.com/html5shiv/3.7.2/html5shiv.min.js
- https://oss.maxcdn.com/respond/1.4.2/respond.min.js
- https://top4top.io/
- https://top4top.io/downloadf-1183zan1c1-zip.html
- https://top4top.io/fileuser-218007.html
- https://connect.facebook.net/en_US/all.js#xfbml=1
- https://top4top.io/report-27366962.html
- https://top4top.io/process/79ad02667e81215ef9fc8bf178072c8e6b961f99
- https://c.top4top.io/f_hqdsbodjug2xT1smxbpqrQ/1636189494/1183zan1c1.zip
- http://download.top4top.io/upload-tool/
- http://top4top.io/call.html
- https://twitter.com/top4top_net
- https://t.me/zSupport
- https://twitter.com/top4top.io
- https://top4top.io
- https://cutt.us.com
- https://0i.is
- https://cutt.us
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787879444&P2=404&P3=2&P4=TBmgCU26SU0Hl4tZi2wSKf%2flmgcZ6KpoNjCWRXjccjs5OrEFgiidK24Z6GeqYKUek6UZxIHhH0EPp4aWL68R%2fA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
Embedded domains
- s.top4top.io
- ajax.googleapis.com
- oss.maxcdn.com
- top4top.io
- connect.facebook.net
- c.top4top.io
- download.top4top.io
- twitter.com
- t.me
- cutt.us.com
- cutt.us
- www.google-analytics.com
- 0i.is
Embedded IP addresses
- 4.150.223.110
- 52.123.252.215
- 40.84.85.40
- 4.230.171.124
- 20.247.184.197
- 52.123.252.248
- 135.232.92.34
- 74.179.77.204
- 135.232.92.97
- 135.233.95.144
- 203.26.79.13
- 13.69.116.107
- 52.123.252.231
- 52.123.129.14
- 20.236.44.162
- 52.123.128.14
- 135.233.45.221
- 52.148.114.188
- 52.168.117.168
- 4.150.223.96
- 72.153.5.140
- 48.200.63.27
- 20.42.65.91
- 52.168.117.174
- 52.110.12.53
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report