MALICIOUS — e3358f1eb6e1975d67dab81a988cb066e7e79cbfcce4452ab4febc44d88fb849
MALICIOUS — e3358f1eb6e1975d67dab81a988cb066e7e79cbfcce4452ab4febc44d88fb849 is a script sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the HiddenSpam family. 4 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e3358f1eb6e1975d67dab81a988cb066e7e79cbfcce4452ab4febc44d88fb849 - SHA-1:
19acfd8843bd1d8da6c34594684b2260e29df920 - MD5:
a50066bc2eb05fc5df2b4761f4e46f71 - ssdeep:
384:i14PpHlHFmevuqoqY6mywdFSiBAyoztVN7NZMC9NxWEiLrHZmV78oEC:i1SFHFmevR5YyOuyyND9N0JHU - TLSH:
T1DF28D704235935D569F84B4BD44888B8C0C2FD1BA13375F6CBACAF92906D6B268E7347 - Submitted as: e3358f1eb6e1975d67dab81a988cb066e7e79cbfcce4452ab4febc44d88fb849
- File type: script · Size: 17438 bytes
- Verdict: malicious (99/100) · Family: HiddenSpam
Detections (4 of 54 engines)
- ClamAV (daily): Js.Trojan.Obfus-633
- Microsoft Defender: Trojan:JS/HideLink.A
- Emsisoft (Emergency Kit): Generic.JS.HiddenSpam.1.5B281E6A
- Kaspersky (KVRT): Trojan-Downloader.JS.Agent.hbs
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Js.Trojan.Obfus-633 (rule
Js.Trojan.Obfus-633) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:JS/HideLink.A (rule
Trojan:JS/HideLink.A) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Generic.JS.HiddenSpam.1.5B281E6A (rule
Generic.JS.HiddenSpam.1.5B281E6A) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan-Downloader.JS.Agent.hbs (rule
Trojan-Downloader.JS.Agent.hbs) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://www.themarkweiss.com, http://gmpg.org/xfn/11, http://themarkweiss.com/blog/wp-content/themes/twentyten/style.css - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
18368 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- 76.0.240.10.in-addr.arpa.
- 1.0.240.10.in-addr.arpa.
- 251.0.0.224.in-addr.arpa.
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 252.0.0.224.in-addr.arpa.
- tas02.sls.update.microsoft.com
- v10.events.data.microsoft.com
- 61.240.178.74.in-addr.arpa.
- 88.65.42.20.in-addr.arpa.
- settings-win.data.microsoft.com
Embedded URLs
- http://www.themarkweiss.com
- http://gmpg.org/xfn/11
- http://themarkweiss.com/blog/wp-content/themes/twentyten/style.css
- http://themarkweiss.com/blog/xmlrpc.php
- http://themarkweiss.com/blog/feed/
- http://themarkweiss.com/blog/comments/feed/
- http://themarkweiss.com/blog/2011/01/12/the-melting-point-of-wax/feed/
- http://themarkweiss.com/blog/wp-includes/js/comment-reply.js?ver=20090102
- http://themarkweiss.com/blog/wp-includes/js/jquery/jquery.js?ver=1.7.1
- http://themarkweiss.com/blog/wp-content/plugins/google-analyticator/external-tracking.min.js?ver=6.2
- http://themarkweiss.com/blog/xmlrpc.php?rsd
- http://themarkweiss.com/blog/wp-includes/wlwmanifest.xml
- http://themarkweiss.com/blog/2010/12/14/hello-world/
- http://themarkweiss.com/blog/2011/04/19/the-best-steve-jobs-quote-ever/
- http://themarkweiss.com/blog/2011/01/12/the-melting-point-of-wax/
- http://themarkweiss.com/blog/?p=12
- http://ronaldheft.com/code/analyticator/
- http://thehousethatjackbuilt.fr/
- http://www.acosa.org/
- http://chalkfarmdesign.com.au/
- http://anthonyshadid.com/
- http://www.trashbags.net.au/
- http://mercyships.org.za/
- http://flickrslideshow.com/
- http://www.berkeleycouncilwatch.com/
Embedded domains
- www.themarkweiss.com
- gmpg.org
- themarkweiss.com
- ronaldheft.com
- google-analytics.com
- thehousethatjackbuilt.fr
- www.acosa.org
- chalkfarmdesign.com.au
- anthonyshadid.com
- www.trashbags.net.au
- mercyships.org.za
- flickrslideshow.com
- www.berkeleycouncilwatch.com
- librarycopyright.net
- allfootballgames.co.uk
- www.cyclopedie.fr
- opengear.org.uk
- www.africansinvermont.org
- whiteprivilegeconference.com
- www.anitakunz.com
- download.macromedia.com
- www.youtube.com
- wordpress.org
- x2.c.lencr.org
- ye.c.lencr.org
Embedded IP addresses
- 34.244.58.147
- 172.215.188.225
- 57.154.63.210
- 4.150.223.105
- 40.84.97.4
- 74.178.240.61
- 125.56.205.32
- 172.215.188.232
- 4.230.171.124
- 125.56.205.24
- 52.230.59.222
- 20.184.175.7
- 74.179.77.204
- 52.178.17.2
- 20.42.65.88
- 4.247.188.224
More HiddenSpam samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report