MALICIOUS — e294d7ebb555ee605c53f87cccb6e3901e3db24ef1021d99f0ada84e12d89959
MALICIOUS — e294d7ebb555ee605c53f87cccb6e3901e3db24ef1021d99f0ada84e12d89959 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 1 of 50 detection engines flagged it.
Identification
- SHA-256:
e294d7ebb555ee605c53f87cccb6e3901e3db24ef1021d99f0ada84e12d89959 - SHA-1:
c960af413606e9463135cedfb3651a102b834393 - MD5:
442910ee06418f5589898a86b85402b7 - ssdeep:
1536:Yb7el1ukruImnSspBolYAbom68VeHC6/1vnza8FLHBI1+:e7eqkqImfpBKn6/1vpFLHy1+ - TLSH:
T1DA362B2E324E39C658E052663DFC46D490CAC617E57386F5E5A2EF4CD868CA37C88819 - Submitted as: e294d7ebb555ee605c53f87cccb6e3901e3db24ef1021d99f0ada84e12d89959
- File type: html · Size: 63665 bytes
- Verdict: malicious (75/100)
Detections (1 of 50 engines)
- Microsoft Defender: Trojan:HTML/Phish.GSL!MTB
Why this verdict
The malicious score of 75/100 is the fusion of 3 weighted signals:
- Microsoft Defender flagged Trojan:HTML/Phish.GSL!MTB (rule
Trojan:HTML/Phish.GSL!MTB) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css, http://downloadsteam3.blogspot.com/favicon.ico, http://downloadsteam3.blogspot.com/2010/08/left-4-dead-2-crack-funcionando.html - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.google.com/2005/gml/b
- http://www.google.com/2005/gml/data
- http://www.google.com/2005/gml/expr
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css
- http://downloadsteam3.blogspot.com/favicon.ico
- http://downloadsteam3.blogspot.com/2010/08/left-4-dead-2-crack-funcionando.html
- http://downloadsteam3.blogspot.com/feeds/posts/default
- http://downloadsteam3.blogspot.com/feeds/posts/default?alt=rss
- https://www.blogger.com/feeds/448347023324515504/posts/default
- http://downloadsteam3.blogspot.com/feeds/2260758552433353481/comments/default
- http://2.bp.blogspot.com/_KwXbe6UQzLM/S3CWkkDZJcI/AAAAAAAABJc/sOTHK3eN5M8/s320/l4d2_pc_box-e1259427336901.jpg
- http://2.bp.blogspot.com/_KwXbe6UQzLM/S3CWkkDZJcI/AAAAAAAABJc/sOTHK3eN5M8/w1200-h630-p-k-no-nu/l4d2_pc_box-e1259427336901.jpg
- http://templateparadownload.blogspot.com.br/
- http://wwwdownloadsteam3.blogspot.com.br/
- http://i.imgur.com/2S8ft.png
- http://3.bp.blogspot.com/-z-89vCF1kDY/UKRFn22FojI/AAAAAAAAC4M/m6PDgrPaU5k/s1600/Body.gif
- http://i48.tinypic.com/5xr9xz.jpg
- http://i.imgur.com/z1MweLe.jpg
- http://i.imgur.com/tfN5p.png
- http://i.imgur.com/eDAWi.png
- http://i.imgur.com/aBmn5.png
- http://i.imgur.com/hlTs6.png
- http://i.imgur.com/OJmgP.gif
- http://i.imgur.com/X33F9.gif
Embedded domains
- www.w3.org
- www.google.com
- www.blogger.com
- downloadsteam3.blogspot.com
- 2.bp.blogspot.com
- templateparadownload.blogspot.com.br
- wwwdownloadsteam3.blogspot.com.br
- i.imgur.com
- 3.bp.blogspot.com
- i48.tinypic.com
- blogspot.com
- downloadsteam3.blogspot.com.br
- www.clocklink.com
- apis.google.com
- pagead2.googlesyndication.com
- www.formulariopro.pog.com.br
- img245.imageshack.us
- hotmail.com
- i39.tinypic.com
- download.macromedia.com
- img392.imageshack.us
- www.macromedia.com
- www.megaupload.com
- img2.blogblog.com
- 4.bp.blogspot.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report