MALICIOUS — e33a5da58ce334a0679705fa90ca632f19e2287329b0f9a489d97fe72d885142
MALICIOUS — e33a5da58ce334a0679705fa90ca632f19e2287329b0f9a489d97fe72d885142 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (91/100). 2 of 54 detection engines flagged it.
Identification
- SHA-256:
e33a5da58ce334a0679705fa90ca632f19e2287329b0f9a489d97fe72d885142 - SHA-1:
d5653ffcf6b2e183d9c75f83093bc7eb14b4397c - MD5:
b1bd3b97f28375037837ad85725ea541 - ssdeep:
768:/uFe7BVfNINRmL2MqGNZSlZyU4YmZtoqbHqDJobi:/u1/mZtoqbHLi - TLSH:
T15A2DF60B6518769F08E0421229BC93E450CFDE2BA17354F9D5A2EF48BC6CE217CD8C68 - Submitted as: e33a5da58ce334a0679705fa90ca632f19e2287329b0f9a489d97fe72d885142
- File type: html · Size: 27075 bytes
- Verdict: malicious (91/100)
Detections (2 of 54 engines)
- Microsoft Defender: Trojan:JS/Redirector.PP
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 91/100 is the fusion of 6 weighted signals:
- Microsoft Defender flagged Trojan:JS/Redirector.PP (rule
Trojan:JS/Redirector.PP) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 19 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/204402360-widget_css_bundle.css, http://colheitafelizgrupo.blogspot.com/favicon.ico, http://colheitafelizgrupo.blogspot.com/feeds/posts/default - static signal, weight 0.35, confidence 0.60
- Extracted generic config (14 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
279 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- desktop-hsgcbep
- login.live.com
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- officeclient.microsoft.com
- www.msn.com
- odc.officeapps.live.com
- tas02.sls.update.microsoft.com
- settings-win.data.microsoft.com
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.google.com/2005/gml/b
- http://www.google.com/2005/gml/data
- http://www.google.com/2005/gml/expr
- https://www.blogger.com/static/v1/widgets/204402360-widget_css_bundle.css
- http://colheitafelizgrupo.blogspot.com/favicon.ico
- http://colheitafelizgrupo.blogspot.com/2011/07/
- http://colheitafelizgrupo.blogspot.com/feeds/posts/default
- http://colheitafelizgrupo.blogspot.com/feeds/posts/default?alt=rss
- https://www.blogger.com/feeds/5032338785743674946/posts/default
- http://1.bp.blogspot.com/-_FUb97qZA0s/TkA4CdmWs6I/AAAAAAAAApc/Uf7NSuRq6eU/s1600/fundo.png
- http://4.bp.blogspot.com/-NYiaVYMx8xI/TwODCP2VJ8I/AAAAAAAADS0/rQYh7mU5zW4/s1600/modelo+antigo.png
- http://2.bp.blogspot.com/-aTHyKRoTSTg/TkA08Vcc8TI/AAAAAAAAApU/nlMjdN-noWk/s1600/meio.png
- http://i54.tinypic.com/2qbhqfo.png
- http://i53.tinypic.com/30ivpxs.png
- http://1.bp.blogspot.com/-_wvA-Vn28ns/TkRNwzOn1tI/AAAAAAAAArU/u-VnUS6xop4/s1600/footer.png
- https://www.blogger.com/dyn-css/authorization.css?targetBlogID=5032338785743674946&
- http://blogergadgets.googlecode.com/files/blogger-page-navi.v2.js
- https://apis.google.com/js/plusone.js
- http://www.grupocolheitafeliz.com.br/p/chat-do-grupo-colheita-feliz.html
- http://3.bp.blogspot.com/-0xjuNNjcOak/TkRILcrTIJI/AAAAAAAAAq4/Fpnh6apF8lI/s1600/Chat.png
- http://www.grupocolheitafeliz.com.br
- http://1.bp.blogspot.com/-5x9QJuLeawQ/TkRINcH3fGI/AAAAAAAAArI/w9tapLMysA0/s1600/Itens-Off.png
- http://colheitafelizgrupo.blogspot.com/
- http://1.bp.blogspot.com/-ilU_g7qXXSc/TkRIM5Hf_4I/AAAAAAAAArE/BLsKxQVEoSk/s1600/home.png
Embedded domains
- www.w3.org
- www.google.com
- www.blogger.com
- colheitafelizgrupo.blogspot.com
- 1.bp.blogspot.com
- 4.bp.blogspot.com
- 2.bp.blogspot.com
- i54.tinypic.com
- i53.tinypic.com
- blogspot.com
- blogergadgets.googlecode.com
- apis.google.com
- pagead2.googlesyndication.com
- www.grupocolheitafeliz.com.br
- 3.bp.blogspot.com
- www.blogblog.com
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 4.207.44.74
- 57.155.104.224
- 135.232.92.137
- 4.230.171.124
- 20.184.175.5
- 74.178.240.51
- 4.150.223.104
- 52.253.84.76
- 52.168.117.168
- 20.42.73.28
- 104.18.33.89
- 125.56.205.42
- 125.56.205.17
- 52.148.114.188
- 72.153.5.128
- 52.110.12.49
- 52.110.12.51
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report