MALICIOUS — e33899e6e6a30768961e456fff075aaa723b54d5d66821fa3b36982f1f1e89c3
MALICIOUS — e33899e6e6a30768961e456fff075aaa723b54d5d66821fa3b36982f1f1e89c3 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (74/100). 0 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e33899e6e6a30768961e456fff075aaa723b54d5d66821fa3b36982f1f1e89c3 - SHA-1:
3b2c635351b1504d293a92d0a8e9d2c6952392f0 - MD5:
b158dba034b30511f3d07b7f2ef4ee97 - ssdeep:
6144:8qcN7+3ggBjHdORjlIlUlQV17nWFl3lcCRdD5Fte:8qcN7+3gArjWFl3lze - TLSH:
T1904819B279C5B789C849403ABFD854A5B047D727646630EDE2E89B8CC860C60ECDC67D - Submitted as: e33899e6e6a30768961e456fff075aaa723b54d5d66821fa3b36982f1f1e89c3
- File type: html · Size: 352259 bytes
- Verdict: malicious (74/100)
Detections (0 of 54 engines)
No engine flagged this sample.
MITRE ATT&CK
Why this verdict
The malicious score of 74/100 is the fusion of 6 weighted signals:
- Obfuscated javascript script: download, dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 24 external host(s) and 9 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css, https://ujyaalochitwan.blogspot.com/favicon.ico, https://ujyaalochitwan.blogspot.com/feeds/posts/default - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (15 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
11649 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- 1.0.240.10.in-addr.arpa.
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 252.0.0.224.in-addr.arpa.
- tas02.sls.update.microsoft.com
- v10.events.data.microsoft.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- ecs.office.com
- update.googleapis.com
- desktop-hsgcbep
- login.live.com
- ctldl.windowsupdate.com
- self.events.data.microsoft.com
- 251.0.0.224.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 1.0.240.10.in-addr.arpa
Embedded URLs
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css
- https://ujyaalochitwan.blogspot.com/favicon.ico
- https://ujyaalochitwan.blogspot.com/2014/10/blog-post.html
- https://ujyaalochitwan.blogspot.com/feeds/posts/default
- https://ujyaalochitwan.blogspot.com/feeds/posts/default?alt=rss
- https://www.blogger.com/feeds/1218425079316799059/posts/default
- https://ujyaalochitwan.blogspot.com/feeds/2467851248111648354/comments/default
- https://2.bp.blogspot.com/-XeM1yRqOh7w/VDS8m7r8l8I/AAAAAAAAACM/zlG_O11XcqM/s640/1161.jpg
- https://2.bp.blogspot.com/-XeM1yRqOh7w/VDS8m7r8l8I/AAAAAAAAACM/zlG_O11XcqM/w1200-h630-p-k-no-nu/1161.jpg
- http://css3-mediaqueries-js.googlecode.com/svn/trunk/css3-mediaqueries.js
- http://themeforest.net/user/MKRdezign
- https://s.graphiq.com/sites/default/files/2307/media/images/Baby_Blue_429626_i0.png
- http://www.istockphoto.com/file_closeup.php?id=5721536&platform=blogger
- https://lh3.googleusercontent.com/-FiCzyOK4Mew/T4aAj2uVJKI/AAAAAAAAPaY/x23tjGIH7ls/s32/ajax-loader.gif
- https://www.blogger.com/dyn-css/authorization.css?targetBlogID=1218425079316799059&
- http://schema.org/WebPage
- https://ajax.googleapis.com/ajax/libs/jquery/1.8.3/jquery.min.js
- http://1.bp.blogspot.com/-htG7vy9vIAA/Tp0KrMUdoWI/AAAAAAAABAU/e7XkFtErqsU/s72-c/grey.gif
- http://brandonaaron.net
- http://img.youtube.com/vi/
- http://www.facebook.com/share.php?u=
- https://twitter.com/intent/tweet?text=
- https://plus.google.com/share?url=
- http://github.com/rhodimus/jQuery-News-Ticker
- http://manos.malihu.gr
Embedded domains
- www.blogger.com
- ujyaalochitwan.blogspot.com
- 2.bp.blogspot.com
- plus.google.com
- css3-mediaqueries-js.googlecode.com
- fonts.googleapis.com
- netdna.bootstrapcdn.com
- fonts.gstatic.com
- themeforest.net
- s.graphiq.com
- themes.googleusercontent.com
- www.istockphoto.com
- 4.bp.blogspot.com
- 1.bp.blogspot.com
- 3.bp.blogspot.com
- lh3.googleusercontent.com
- blogspot.com
- schema.org
- ajax.googleapis.com
- brandonaaron.net
- ytimg.googleusercontent.com
- youtu.be
- youtube.com
- img.youtube.com
- www.facebook.com
Embedded IP addresses
- 74.178.240.61
- 52.123.129.14
- 4.150.223.114
- 40.84.97.4
- 172.172.255.217
- 135.232.92.137
- 52.123.128.14
- 20.184.175.11
- 20.89.1.13
- 72.145.35.110
- 72.145.35.97
- 74.178.76.128
- 40.84.85.40
- 48.211.4.16
- 20.184.175.15
- 85.210.193.152
- 172.215.188.232
- 4.247.188.233
- 57.154.63.210
- 172.215.188.225
- 4.150.223.102
- 52.148.114.188
- 4.247.188.224
- 57.155.104.224
- 20.184.175.2
File paths
- s:\)\)+/g,
- s:\)+/g,
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report