MALICIOUS — e33eb934e1a2d8c7547e37e3221e4be887662736bbc7216b1e656e7260e9a4c3
MALICIOUS — e33eb934e1a2d8c7547e37e3221e4be887662736bbc7216b1e656e7260e9a4c3 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the Iframeinject family. 2 of 54 detection engines flagged it.
Identification
- SHA-256:
e33eb934e1a2d8c7547e37e3221e4be887662736bbc7216b1e656e7260e9a4c3 - SHA-1:
56de6ea32d01c003595aee66d8d0422dc12ff3d4 - MD5:
e8269677dab75212c6384c480cca18e7 - ssdeep:
768:H9T0EipBrq2t61F191QSXwQkelpr4qFziX:dTupBrq2t6nPeSXwPgF4qFk - TLSH:
T1BD33B664374A39CB34A08152E77C05A8E5C8C5E7F93342B1D59FF98168B8C706D2BC96 - Submitted as: e33eb934e1a2d8c7547e37e3221e4be887662736bbc7216b1e656e7260e9a4c3
- File type: html · Size: 51307 bytes
- Verdict: malicious (92/100) · Family: Iframeinject
Detections (2 of 54 engines)
- Microsoft Defender: Trojan:JS/Iframeinject.AH
- Kaspersky (KVRT): Trojan-Downloader.JS.Iframe.dfw
Why this verdict
The malicious score of 92/100 is the fusion of 7 weighted signals:
- Microsoft Defender flagged Trojan:JS/Iframeinject.AH (rule
Trojan:JS/Iframeinject.AH) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan-Downloader.JS.Iframe.dfw (rule
Trojan-Downloader.JS.Iframe.dfw) - engine signal, weight 0.55, confidence 0.85 - Obfuscated powershell script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 2 external host(s) and 4 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css, http://keywebtracker.com/?if=1&scr_w=, http://zippoforshurik.blogspot.com/favicon.ico - static signal, weight 0.35, confidence 0.60
- Extracted generic config (13 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
280 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- officeclient.microsoft.com
- www.msn.com
- odc.officeapps.live.com
- licensing.mp.microsoft.com
- assets.msn.com
- www.bing.com
- th.bing.com
- edge.microsoft.com
- v10.events.data.microsoft.com
- time.windows.com
- ctldl.windowsupdate.com
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.google.com/2005/gml/b
- http://www.google.com/2005/gml/data
- http://www.google.com/2005/gml/expr
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css
- http://keywebtracker.com/?if=1&scr_w=
- http://zippoforshurik.blogspot.com/favicon.ico
- http://zippoforshurik.blogspot.com/2011/08/billie-chest-tattoo-were.html
- http://zippoforshurik.blogspot.com/feeds/posts/default
- http://zippoforshurik.blogspot.com/feeds/posts/default?alt=rss
- https://draft.blogger.com/feeds/6317919260688502841/posts/default
- http://zippoforshurik.blogspot.com/feeds/805246282570210151/comments/default
- http://i295.photobucket.com/albums/mm132/SuperiorTattoo/20403listing.jpg
- https://lh5.googleusercontent.com/proxy/PMNdY_PhGOODTpDr5-mPfGm6Y-JkjsXwUHffhVZB3zvvltamH-CRl2_1EiftrEG5fPvXUugVvP05Dlu0BtqMAO5kIYAiI-T39BqzUFq9qBKf0Wedq5JGsoL2sIM=w1200-h630-p-k-no-nu
- https://draft.blogger.com/dyn-css/authorization.css?targetBlogID=6317919260688502841&
- https://apis.google.com/js/plusone.js
- http://zippoforshurik.blogspot.com/
- http://img15.imageshack.us/img15/6923/41700709200bf3424cf6b.jpg
- http://www.photofunblog.com/wp-content/uploads/2011/02/Shoulder-Tribal-Tattoo-2011-Design-for-Guys.jpg
- http://www.tattoospotter.com/media/import/Skulls.jpg
- http://img60.imageshack.us/img60/3514/0811082254qm9.jpg
- http://www.tattoodesignpictures.net/tattoo-design-picture-blown-monaxle.jpg
- http://fc08.deviantart.net/fs10/f/2006/324/a/0/A_Few_Tattoo_Designs_by_deargodeverything.jpg
- http://ny-image3.etsy.com/il_fullxfull.88114771.jpg
- http://www.tattoosdaily.com/chest-tattoo/chest-tattoo-215333_0724.jpg
Embedded domains
- www.w3.org
- www.google.com
- www.blogger.com
- keywebtracker.com
- zippoforshurik.blogspot.com
- draft.blogger.com
- i295.photobucket.com
- lh5.googleusercontent.com
- blogspot.com
- apis.google.com
- pagead2.googlesyndication.com
- img15.imageshack.us
- www.photofunblog.com
- www.tattoospotter.com
- img60.imageshack.us
- www.tattoodesignpictures.net
- fc08.deviantart.net
- ny-image3.etsy.com
- www.tattoosdaily.com
- www.uktattoostudios.co.uk
- 1.bp.blogspot.com
- natefury.files.wordpress.com
- www.masterofink.com
- nikadon.com
- www.tattoo-design-pics.com
Embedded IP addresses
- 4.150.223.96
- 52.123.252.219
- 52.253.84.76
- 4.230.171.124
- 172.64.154.167
- 172.66.2.5
- 52.110.12.8
- 52.110.12.32
- 4.150.223.104
- 72.145.35.103
- 52.148.114.188
- 52.110.12.50
- 52.110.12.4
More Iframeinject samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report