SUSPICIOUS — f21c317d56b52b69bdb4ca274641957174445eee9becb32ee3738ca48e49b8cf
SUSPICIOUS — f21c317d56b52b69bdb4ca274641957174445eee9becb32ee3738ca48e49b8cf is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 1 of 53 detection engines flagged it.
Identification
- SHA-256:
f21c317d56b52b69bdb4ca274641957174445eee9becb32ee3738ca48e49b8cf - SHA-1:
14d145ec84243007c81a921519b4fbda4e43681e - MD5:
71ea485dae435904ece3186c66ea341a - ssdeep:
1536:166QaG/Qf3YvOc4EjhcGaNRwdJVQbNYrTMaL+h+HTXujbyeHnfH05xYJjoODENAM:kkG/QfvidJZo0+h+HTXWP05xsjoODOAM - TLSH:
T19339932267F20D9F81CC0411F584585884D1BFDF69B2B4F2866ACF8FE41CA61E8B549B - Submitted as: f21c317d56b52b69bdb4ca274641957174445eee9becb32ee3738ca48e49b8cf
- File type: html · Size: 89648 bytes
- Verdict: suspicious (54/100)
Detections (1 of 53 engines)
- Microsoft Defender: Trojan:JS/CoinHive.A
Why this verdict
The suspicious score of 54/100 is the fusion of 4 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 29 external host(s) at runtime (27 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://gmpg.org/xfn/11, https://indiaisrael.org/xmlrpc.php, https://indiaisrael.org/feed/ - static signal, weight 0.35, confidence 0.60
- Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
277 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- settings-win.data.microsoft.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- licensing.mp.microsoft.com
- windows.msn.com
- oneocsp.microsoft.com
Embedded URLs
- http://gmpg.org/xfn/11
- https://indiaisrael.org/xmlrpc.php
- https://indiaisrael.org/feed/
- https://indiaisrael.org/comments/feed/
- https://indiaisrael.org/wp-includes/css/dist/block-library/style.min.css?ver=5.2.13
- https://indiaisrael.org/wp-content/plugins/woocommerce/assets/css/blocks/style.css?ver=3.6.6
- https://indiaisrael.org/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=5.1.3
- https://indiaisrael.org/wp-content/plugins/yith-woocommerce-wishlist/assets/css/jquery.selectBox.css?ver=1.2.0
- https://indiaisrael.org/wp-content/themes/flatsome/assets/css/fl-icons.css?ver=3.3
- https://indiaisrael.org/wp-content/themes/flatsome/inc/integrations/wc-yith-wishlist/wishlist.css?ver=3.3
- https://indiaisrael.org/wp-content/themes/flatsome/assets/css/flatsome.css?ver=3.4.0
- https://indiaisrael.org/wp-content/themes/flatsome/assets/css/flatsome-shop.css?ver=3.4.0
- https://indiaisrael.org/wp-content/themes/flatsome-child/style.css?ver=3.4.0
- https://indiaisrael.org/wp-includes/js/jquery/jquery.js?ver=1.12.4-wp
- https://indiaisrael.org/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.4.1
- https://api.w.org/
- https://indiaisrael.org/wp-json/
- https://indiaisrael.org/xmlrpc.php?rsd
- https://indiaisrael.org/wp-includes/wlwmanifest.xml
- https://indiaisrael.org/
- https://indiaisrael.org/wp-json/oembed/1.0/embed?url=https%3A%2F%2Findiaisrael.org%2F
- https://indiaisrael.org/wp-json/oembed/1.0/embed?url=https%3A%2F%2Findiaisrael.org%2F&
- https://indiaisrael.org/wp-content/themes/flatsome/assets/css/ie-fallback.css
- https://indiaisrael.org/wp-content/themes/flatsome/assets/libs/ie-flexibility.js
- https://ajax.googleapis.com/ajax/libs/webfont/1/webfont.js
Embedded domains
- gmpg.org
- indiaisrael.org
- coinhive.com
- s.w.org
- api.w.org
- cdnjs.cloudflare.com
- ajax.googleapis.com
- twitter.com
- gmail.com
- www.linkedin.com
- schema.org
Embedded IP addresses
- 40.84.85.40
- 52.168.112.67
- 20.247.184.197
- 4.230.171.124
- 4.247.188.233
- 74.178.76.128
- 20.184.175.4
- 74.178.240.51
- 20.165.94.63
- 4.150.223.97
- 20.112.250.133
- 52.123.128.14
- 52.123.129.14
- 203.26.79.13
- 172.178.240.161
- 172.66.2.5
- 74.179.71.159
- 52.148.114.188
- 52.110.12.38
- 52.110.12.3
- 40.84.97.4
- 72.153.5.60
- 48.192.143.121
- 20.42.65.89
- 52.168.117.169
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report