MALICIOUS — e336ce17fb6e796ba840d04f8d6bb20965d5dd550ad006f7304d44e559e98565
MALICIOUS — e336ce17fb6e796ba840d04f8d6bb20965d5dd550ad006f7304d44e559e98565 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the TrojanClicker family. 2 of 54 detection engines flagged it.
Identification
- SHA-256:
e336ce17fb6e796ba840d04f8d6bb20965d5dd550ad006f7304d44e559e98565 - SHA-1:
45a66faa16d410e8e338129e246c70fde0975563 - MD5:
d1b272e119e28d09d34ccd07f61cd2b9 - ssdeep:
768:iiSS5y5rxgk5git7QBwkhSt0CnLhbFV2X9:3h89xgk5gitEBwkhSt0C9bFk - TLSH:
T19331DA7F7A557B8F08D0801676AC49E490CAC597E573C2B1E2A1FF88E43CC60A855CA7 - Submitted as: e336ce17fb6e796ba840d04f8d6bb20965d5dd550ad006f7304d44e559e98565
- File type: html · Size: 41985 bytes
- Verdict: malicious (98/100) · Family: TrojanClicker
Detections (2 of 54 engines)
- ClamAV (daily): Win.Trojan.Crypt-291
- Microsoft Defender: TrojanClicker:HTML/Iframe
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Crypt-291 (rule
Win.Trojan.Crypt-291) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged TrojanClicker:HTML/Iframe (rule
TrojanClicker:HTML/Iframe) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 16 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css, http://dramamama2b.blogspot.com/favicon.ico, http://dramamama2b.blogspot.com/feeds/posts/default - static signal, weight 0.35, confidence 0.60
- Extracted generic config (14 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
279 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.google.com/2005/gml/b
- http://www.google.com/2005/gml/data
- http://www.google.com/2005/gml/expr
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css
- http://dramamama2b.blogspot.com/favicon.ico
- http://dramamama2b.blogspot.com/2009/03/izzy-had-her-first-doctors-appointment.html
- http://dramamama2b.blogspot.com/feeds/posts/default
- http://dramamama2b.blogspot.com/feeds/posts/default?alt=rss
- https://www.blogger.com/feeds/3639243087081292414/posts/default
- http://dramamama2b.blogspot.com/feeds/188832763336550394/comments/default
- http://randaclay.com
- http://techprevue.blogspot.com
- http://img132.imageshack.us/img132/7414/header2f.jpg
- http://4.bp.blogspot.com/_jA-SP6SAtfY/SrCOsBgFT6I/AAAAAAAABNo/mRr1xtkBjMw/s1600/header1y.jpg
- https://www.blogger.com/dyn-css/authorization.css?targetBlogID=3639243087081292414&
- https://apis.google.com/js/plusone.js
- http://dramamama2b.blogspot.com/
- http://dramamama2b.blogspot.com/feeds/comments/default
- http://blogger.com
- http://dramamama2b.blogspot.com/2008/
- http://dramamama2b.blogspot.com/2008/10/
- http://dramamama2b.blogspot.com/2008/11/
- http://dramamama2b.blogspot.com/2008/12/
- http://dramamama2b.blogspot.com/2009/
Embedded domains
- www.w3.org
- www.google.com
- www.blogger.com
- dramamama2b.blogspot.com
- randaclay.com
- techprevue.blogspot.com
- img132.imageshack.us
- 4.bp.blogspot.com
- blogspot.com
- apis.google.com
- pagead2.googlesyndication.com
- blogger.com
- lh3.googleusercontent.com
- todayscreativelife.com
- feedproxy.google.com
- lh6.googleusercontent.com
- www.jessmcclenahan.com
- houserhappenings.blogspot.com
- newdirectionsaromatics.blogspot.com
- www.mycharmingkids.net
- lh4.googleusercontent.com
- greenwoodhills75080.blogspot.com
- lh5.googleusercontent.com
- andersonarmy.blogspot.com
- dontangertheprincess.blogspot.com
Embedded IP addresses
- 20.50.201.200
- 4.247.188.233
- 4.230.171.124
- 52.230.59.222
- 74.179.77.204
- 20.165.94.54
- 20.50.201.201
- 20.165.94.63
- 4.150.223.108
- 172.215.188.232
- 52.148.114.188
- 52.110.12.20
- 72.145.35.104
- 52.110.12.45
More TrojanClicker samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report