SUSPICIOUS — f991878c8301c5867287f184e22afde71e31f63137a1900794bbfcce873776b8
SUSPICIOUS — f991878c8301c5867287f184e22afde71e31f63137a1900794bbfcce873776b8 is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (49/100). 0 of 54 detection engines flagged it.
Identification
- SHA-256:
f991878c8301c5867287f184e22afde71e31f63137a1900794bbfcce873776b8 - SHA-1:
eb3b9eaad544f21c123c85d259f2cf7440e505ff - MD5:
e24e4edcc4e60cf19d86fe4b6fdf1959 - ssdeep:
48:qkiJVonxXT9djmWVC6gOBfOmiVdwVfVCJ:fifkxXT9zVTvy3whVM - TLSH:
T1A715E7021A3532E5B4E8E153F078B5C516DBEEC7502402EBC4E52BC000A5FE2EE08DD6 - Submitted as: f991878c8301c5867287f184e22afde71e31f63137a1900794bbfcce873776b8
- File type: html · Size: 2197 bytes
- Verdict: suspicious (49/100)
Detections (0 of 54 engines)
No engine flagged this sample.
Why this verdict
The suspicious score of 49/100 is the fusion of 4 weighted signals:
- Contacted 5 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://a.rmgserving.com/rmgjsc/zcFilters.js?1, http://info-active-ads-notify-recovered-support-identify.ml/?ga=wuQ19siOhrqSflUbX0aMJyFfLar8kcOW11xmKbB7GTVnVdnI%2BlnNionNlz9jHKHi%2FfWvQHt2orlDfJDtIgypVJSvxBNRIYTX%2BqIVQFs7v3vjM8myXXdIgh6gnQLvY%2BClD546esnKuY3c27mXE%2FX%2FLkCdLu21T3awF%2BfVVfVnsFftAYbMiiLbcK%2B2ZZ%2By39bxkR4iEbh7PZ%2BOYMxofWEevQ%3D%3D&gerf=jVPrucuHd7TjrwgJoN6%2BUl5CtrUxMoojF4pO14sEGr8%3D&guro=cnc9BZ7iQxni5FsWst5w0ic4EC46uKvwVj%2BWL%2Fj62aokyNS0C%2Fv0YUrQhC6PQVoTD6Q5EuOXfxlDkEjz%2BYR0NcHSb%2Fx38OPZsRVfdMwOoxM%3D&, http://info-active-ads-notify-recovered-support-identify.ml/rg-erdr.php?_rpo=t - static signal, weight 0.35, confidence 0.60
- Extracted generic config (3 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
276 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- fe3cr.delivery.mp.microsoft.com
- v10.events.data.microsoft.com
- slscr.update.microsoft.com
Embedded URLs
- http://a.rmgserving.com/rmgjsc/zcFilters.js?1
- http://info-active-ads-notify-recovered-support-identify.ml/?ga=wuQ19siOhrqSflUbX0aMJyFfLar8kcOW11xmKbB7GTVnVdnI%2BlnNionNlz9jHKHi%2FfWvQHt2orlDfJDtIgypVJSvxBNRIYTX%2BqIVQFs7v3vjM8myXXdIgh6gnQLvY%2BClD546esnKuY3c27mXE%2FX%2FLkCdLu21T3awF%2BfVVfVnsFftAYbMiiLbcK%2B2ZZ%2By39bxkR4iEbh7PZ%2BOYMxofWEevQ%3D%3D&gerf=jVPrucuHd7TjrwgJoN6%2BUl5CtrUxMoojF4pO14sEGr8%3D&guro=cnc9BZ7iQxni5FsWst5w0ic4EC46uKvwVj%2BWL%2Fj62aokyNS0C%2Fv0YUrQhC6PQVoTD6Q5EuOXfxlDkEjz%2BYR0NcHSb%2Fx38OPZsRVfdMwOoxM%3D&
- http://info-active-ads-notify-recovered-support-identify.ml/rg-erdr.php?_rpo=t
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- a.rmgserving.com
- info-active-ads-notify-recovered-support-identify.ml
Embedded IP addresses
- 4.150.223.97
- 4.144.132.114
- 4.230.171.124
- 20.165.94.54
- 52.182.143.212
- 74.178.76.128
- 20.42.179.204
- 92.223.78.30
- 72.153.5.60
- 52.148.114.188
- 52.110.12.11
- 52.110.12.26
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report