MALICIOUS — f82cfe4acf5000ffcf8ba974eb47b8402a7bed6b70e392019e8e25697e780bd0
MALICIOUS — f82cfe4acf5000ffcf8ba974eb47b8402a7bed6b70e392019e8e25697e780bd0 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the TrojanClicker family. 2 of 54 detection engines flagged it.
Identification
- SHA-256:
f82cfe4acf5000ffcf8ba974eb47b8402a7bed6b70e392019e8e25697e780bd0 - SHA-1:
4db2f7ae56d5a640025c159ea54fdd15fcccf8d0 - MD5:
b66fdf738d16957b30921f467aa46483 - ssdeep:
1536:1BXZSl75WcHdxWR6siC9KO9J0bzzbVnyOB6qUi3D/k:1BXZS15WcHej2O9J0bzzbVyOsqU2D/k - TLSH:
T17F36B42E2A1A778B04E0951678AC8FD5C1CA8A53F923C0F5F5B37B848474D78DC0A993 - Submitted as: f82cfe4acf5000ffcf8ba974eb47b8402a7bed6b70e392019e8e25697e780bd0
- File type: html · Size: 67527 bytes
- Verdict: malicious (92/100) · Family: TrojanClicker
Detections (2 of 54 engines)
- Microsoft Defender: TrojanClicker:JS/Faceliker.N
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 92/100 is the fusion of 7 weighted signals:
- Microsoft Defender flagged TrojanClicker:JS/Faceliker.N (rule
TrojanClicker:JS/Faceliker.N) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 5 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css, http://tarihinarkaodasi.blogspot.com/favicon.ico, http://tarihinarkaodasi.blogspot.com/feeds/posts/default - static signal, weight 0.35, confidence 0.60
- Extracted generic config (16 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
281 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
- licensing.mp.microsoft.com
- www.bing.com
- fe3cr.delivery.mp.microsoft.com
- v10.events.data.microsoft.com
Dropped files
- 9df288d7098c73a9fa5fd19c46ca81266b7c841420ea36617cd9587196703e54 -
9df288d7098c73a9fa5fd19c46ca81266b7c841420ea36617cd9587196703e54
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.google.com/2005/gml/b
- http://www.google.com/2005/gml/data
- http://www.google.com/2005/gml/expr
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css
- http://tarihinarkaodasi.blogspot.com/favicon.ico
- http://tarihinarkaodasi.blogspot.com/2010/10/tarihin-arka-odas-4-aralk-2010.html
- http://tarihinarkaodasi.blogspot.com/feeds/posts/default
- http://tarihinarkaodasi.blogspot.com/feeds/posts/default?alt=rss
- https://draft.blogger.com/feeds/3261434242168376568/posts/default
- http://tarihinarkaodasi.blogspot.com/feeds/5344391881522335346/comments/default
- http://blogandweb.com/
- http://btemplates.com/
- http://www.woothemes.com/
- http://2.bp.blogspot.com/_73i0fjAB_Hw/SRs1WaCDX3I/AAAAAAAAAlk/QkZqPSVF3fQ/s1600/top.gif
- http://4.bp.blogspot.com/_73i0fjAB_Hw/SRs1ZrwA-TI/AAAAAAAAAoM/j0HTo3pIBzg/s1600/menu_bg.gif
- http://4.bp.blogspot.com/_73i0fjAB_Hw/SRs1ZNMCS7I/AAAAAAAAAnk/HRqTa7XFZk0/s1600/menu_button.gif
- http://2.bp.blogspot.com/_73i0fjAB_Hw/SRs1WCQAwnI/AAAAAAAAAlc/ptyixVX9D4g/s1600/content_bg.gif
- http://4.bp.blogspot.com/_73i0fjAB_Hw/SRs1YZkt-TI/AAAAAAAAAms/aEjKC2E3GpE/s1600/post_element.gif
- http://4.bp.blogspot.com/_73i0fjAB_Hw/SRs1XloU6LI/AAAAAAAAAmM/CwZLoazYb0o/s1600/icon_author.gif
- http://3.bp.blogspot.com/_73i0fjAB_Hw/SRs1XyKOhGI/AAAAAAAAAmU/eEMveMzzghM/s1600/icon_comment.gif
- http://4.bp.blogspot.com/_73i0fjAB_Hw/SRs1Ya9d6JI/AAAAAAAAAm0/Eg6cciY1sE4/s1600/sidebar_block_top.gif
- http://3.bp.blogspot.com/_73i0fjAB_Hw/SRs1XbdI8YI/AAAAAAAAAl8/Za1-gZw965w/s1600/circle.gif
- http://1.bp.blogspot.com/_73i0fjAB_Hw/SRs1ZXr-GBI/AAAAAAAAAns/U8x9F9CAIh8/s1600/sidebar_ul_lines.gif
- http://1.bp.blogspot.com/_73i0fjAB_Hw/SRs1XnTBGcI/AAAAAAAAAmE/WwBYmYMeLvw/s1600/icon_folder.gif
Embedded domains
- www.w3.org
- www.google.com
- www.blogger.com
- tarihinarkaodasi.blogspot.com
- draft.blogger.com
- blogandweb.com
- btemplates.com
- www.woothemes.com
- 2.bp.blogspot.com
- 4.bp.blogspot.com
- 3.bp.blogspot.com
- 1.bp.blogspot.com
- blogspot.com
- apis.google.com
- pagead2.googlesyndication.com
- www.facebook.com
- like.style.top
- srv.sayyac.com
- www.sayyac.com
- kadinelbisemodelleri.com
- mobilyadekorasyonnn.info
- sakizimu.blogspot.com
- kpssdestek.blogspot.com
- minimum-system-requirements.blogspot.com
- woothemes.com
Embedded IP addresses
- 13.89.179.12
- 4.230.171.124
- 20.247.184.142
- 85.210.196.11
- 74.178.240.51
- 4.150.223.96
- 74.178.76.128
- 20.165.94.63
- 92.223.78.30
- 20.42.65.91
- 4.207.44.66
- 72.153.5.137
- 52.148.114.188
- 52.110.12.19
- 52.110.12.44
More TrojanClicker samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report