MALICIOUS — e0ddc6ff7a872010620a19ad7b3b26f32c45eceef3a04071cfd166d12acd7872
MALICIOUS — e0ddc6ff7a872010620a19ad7b3b26f32c45eceef3a04071cfd166d12acd7872 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (83/100), attributed to the Ramnit family. 3 of 53 detection engines flagged it.
Identification
- SHA-256:
e0ddc6ff7a872010620a19ad7b3b26f32c45eceef3a04071cfd166d12acd7872 - SHA-1:
b78ff8ef4deda371342f13ed73b019812c8cc187 - MD5:
7893539c783d2a48e882727603f927ca - ssdeep:
6144:pHiesMYod+X3oI+Y/sMYod+X3oI+YLsMYod+X3oI+YQ:1ic5d+X3F5d+X315d+X3+ - TLSH:
T11E48C0955072E18F0907AB9B522F769CDE5EE0E6420B3AC0459FBB8F1819540FF824E7 - Submitted as: e0ddc6ff7a872010620a19ad7b3b26f32c45eceef3a04071cfd166d12acd7872
- File type: html · Size: 375650 bytes
- Verdict: malicious (83/100) · Family: Ramnit
Detections (3 of 53 engines)
- Microsoft Defender: Virus:VBS/Ramnit.gen!C
- Emsisoft (Emergency Kit): Trojan.HTML.Ramnit.A
- Kaspersky (KVRT): Trojan-Dropper.VBS.Agent.bp
Why this verdict
The malicious score of 83/100 is the fusion of 5 weighted signals:
- Memory forensics: 2 finding(s), e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.50, confidence 0.85 - Obfuscated powershell script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 30 external host(s) at runtime (27 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://www.nsw88.com, https://hm.baidu.com/hm.js?3f59711b6e16a4e8b6d8758e7eb0d66b, http://yc.jbl22.com/Help/ - static signal, weight 0.35, confidence 0.60
- Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
286 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- msedge.api.cdp.microsoft.com
Dropped files
- 10c59a8c3c2c45b50cf349471cca0b43ea9ce0d0a06c40b8c4e108e4acedd471 -
10c59a8c3c2c45b50cf349471cca0b43ea9ce0d0a06c40b8c4e108e4acedd471
Embedded URLs
- http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd
- http://www.w3.org/1999/xhtml
- http://www.nsw88.com
- https://hm.baidu.com/hm.js?3f59711b6e16a4e8b6d8758e7eb0d66b
- http://yc.jbl22.com/Help/
- http://yc.jbl22.com/Help/Leaveword.aspx
- http://yc.jbl22.com/Helps/ContactUs.html
- http://yc.jbl22.com/Sitemap.html
- http://yc.jbl22.com/xinjianxiaoqu/dichanxiaoqujingguan.html
- http://yc.jbl22.com/Helps/jingguanshuichuligon.html
- http://yc.jbl22.com/project/
- http://yc.jbl22.com/yuchishejijianzaogon.shtml
- http://yc.jbl22.com/yuchiguolvqicai.shtml
- http://yc.jbl22.com/Agent/
- http://yc.jbl22.com/Helps/aboutus.html
- http://yc.jbl22.com/Projects/bieshujiatingjinggua.html
- http://yc.jbl22.com/jingguanshuichulizhi.shtml
- http://bdimg.share.baidu.com/static/js/shell_v2.js?cdnversion=
- http://yc.jbl22.com/UploadFiles/FCK/2016-09/201609248Z4RX8X264.png
- http://yc.jbl22.com/UploadFiles/FCK/2016-09/20160924LZJ480FVVB.jpg
- http://yc.jbl22.com/xianyoudichan/tingyuanyuchisheji.html
- http://yc.jbl22.com/
- http://yc.jbl22.com
- http://yc.jbl22.com/UploadFiles/FCK/2016-10/20161002860NTJVLJZ.png
- http://yc.jbl22.com/Article/yuchishejijianzao_1.html
Embedded domains
- www.w3.org
- hotmail.com
- qq.com
- www.nsw88.com
- hm.baidu.com
- yc.jbl22.com
- bdimg.share.baidu.com
- www.miitbeian.gov.cn
- weibo.com
- t.qq.com
Embedded IP addresses
- 52.168.117.174
- 52.123.252.227
- 52.123.252.242
- 4.230.171.124
- 52.253.84.76
- 20.42.179.204
- 52.123.252.212
- 20.165.94.46
- 74.178.240.61
- 135.232.92.97
- 51.104.15.252
- 135.233.95.144
- 203.26.79.13
- 52.123.252.244
- 40.104.4.2
- 20.76.201.171
- 52.123.128.14
- 40.99.133.242
- 52.123.129.14
- 172.178.240.161
- 92.223.78.30
- 52.148.114.188
- 72.153.5.137
- 172.170.180.133
- 20.42.65.88
More Ramnit samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report