SUSPICIOUS — f5563c2e7fa90056b59e1170bccc1c887965990c234c53dd5b4f0dac97fae20c
SUSPICIOUS — f5563c2e7fa90056b59e1170bccc1c887965990c234c53dd5b4f0dac97fae20c is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (42/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
f5563c2e7fa90056b59e1170bccc1c887965990c234c53dd5b4f0dac97fae20c - SHA-1:
4a6032f2a9e7a0db62724dec0d39a31e50238369 - MD5:
8e9ee9ca2c578247b783b668de1b3e69 - ssdeep:
384:EBspUM0PTDzP4G0p7wlEh+tn3hRY06IWOtE3VLWyINjgyoOb+ae0z8xQ/Fz/z8Yc:EqpUpTfP4OzY0lvqC91fTgKh3rGZ - TLSH:
T1592CB6C7975732B9A389048B1220CD679545280EBC30AA7E637C57305F5C9A3E88FF66 - Submitted as: f5563c2e7fa90056b59e1170bccc1c887965990c234c53dd5b4f0dac97fae20c
- File type: html · Size: 26261 bytes
- Verdict: suspicious (42/100)
Detections (2 of 50 engines)
- Microsoft Defender: Trojan:JS/Redirector.ARR!MTB
- Kaspersky (KVRT): Trojan-Downloader.HTML.JScript.dj
Why this verdict
The suspicious score of 42/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: defense-evasion (rule
script-deobfuscation) - static signal, weight 0.35, confidence 0.75 - Embedded network infrastructure: http://gmpg.org/xfn/11, http://template.com/wp/?feed=rss2, http://template.com/wp/?feed=rss - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd
- http://www.w3.org/1999/xhtml
- http://gmpg.org/xfn/11
- http://template.com/wp/?feed=rss2
- http://template.com/wp/?feed=rss
- http://template.com/wp/?feed=atom
- http://template.com/wp/xmlrpc.php
- http://template.com/wp/?m=200808
- http://template.com/wp/xmlrpc.php?rsd
- http://template.com/wp/wp-includes/wlwmanifest.xml
- https://wewufiw.tripod.com/lumigan-directions-to-apply-for-eyelashes/
- https://wewufiw.tripod.com/methylprednisolone-contraindications/
- https://wewufiw.tripod.com/predate/
- https://wewufiw.tripod.com/aricept/
- https://wewufiw.tripod.com/yttrium-barium-copper-oxide/
- https://wewufiw.tripod.com/procardia-xl/
- https://wewufiw.tripod.com/catapres-withdrawal/
- https://wewufiw.tripod.com/fmc-talstar-pl-granules/
- http://template.com/wp/
Embedded domains
- www.w3.org
- gmpg.org
- template.com
- wewufiw.tripod.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report