MALICIOUS — f99a40560fbe4e6cb82f96bda6594ae503cf954604a526deaec1db9f41c22296
MALICIOUS — f99a40560fbe4e6cb82f96bda6594ae503cf954604a526deaec1db9f41c22296 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 2 of 54 detection engines flagged it.
Identification
- SHA-256:
f99a40560fbe4e6cb82f96bda6594ae503cf954604a526deaec1db9f41c22296 - SHA-1:
3f0e51fbb9d9bbb18541a75262d4add45f053e70 - MD5:
9c68d05d660e7c6017be2face0a0a82d - ssdeep:
384:tpz8iB9S5y5tDY1/i5A2zwqJc1UxrX3Ik/jJLOE9z+LY+jd62UdllGQDQ4aR46:MirS5y59Y1/i5MMaUxrX3IwjB+b42Uo - TLSH:
T16F2FA56F3A27264B18D088167BAC0EE4D0DAD59BF52380F0E2E2FF44E434D60E959597 - Submitted as: f99a40560fbe4e6cb82f96bda6594ae503cf954604a526deaec1db9f41c22296
- File type: html · Size: 33723 bytes
- Verdict: malicious (98/100)
Detections (2 of 54 engines)
- ClamAV (daily): Win.Trojan.Crypt-291
- Microsoft Defender: TrojanClicker:HTML/Iframe
Why this verdict
The malicious score of 98/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Crypt-291 (rule
Win.Trojan.Crypt-291) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged TrojanClicker:HTML/Iframe (rule
TrojanClicker:HTML/Iframe) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec, defense-evasion (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 2 external host(s) and 16 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css, http://karensheer.blogspot.com/favicon.ico, http://karensheer.blogspot.com/feeds/posts/default - static signal, weight 0.35, confidence 0.60
- Extracted generic config (14 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
279 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- desktop-hsgcbep
- login.live.com
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
Embedded URLs
- http://www.w3.org/1999/xhtml
- http://www.google.com/2005/gml/b
- http://www.google.com/2005/gml/data
- http://www.google.com/2005/gml/expr
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css
- http://karensheer.blogspot.com/favicon.ico
- http://karensheer.blogspot.com/2009/06/
- http://karensheer.blogspot.com/feeds/posts/default
- http://karensheer.blogspot.com/feeds/posts/default?alt=rss
- https://www.blogger.com/feeds/8728008401654031811/posts/default
- http://randaclay.com
- http://techprevue.blogspot.com
- http://img132.imageshack.us/img132/7414/header2f.jpg
- http://4.bp.blogspot.com/_jA-SP6SAtfY/SrCOsBgFT6I/AAAAAAAABNo/mRr1xtkBjMw/s1600/header1y.jpg
- https://www.blogger.com/dyn-css/authorization.css?targetBlogID=8728008401654031811&
- https://apis.google.com/js/plusone.js
- http://karensheer.blogspot.com/
- http://karensheer.blogspot.com/feeds/comments/default
- http://blogger.com
- http://karensheer.blogspot.com/2011/
- http://karensheer.blogspot.com/2011/06/
- http://karensheer.blogspot.com/2011/04/
- http://karensheer.blogspot.com/2011/01/
- http://karensheer.blogspot.com/2010/
- http://karensheer.blogspot.com/2010/12/
Embedded domains
- www.w3.org
- www.google.com
- www.blogger.com
- karensheer.blogspot.com
- randaclay.com
- techprevue.blogspot.com
- img132.imageshack.us
- 4.bp.blogspot.com
- blogspot.com
- apis.google.com
- pagead2.googlesyndication.com
- blogger.com
- resources.blogblog.com
- www.blogblog.com
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 52.178.17.234
- 52.230.60.54
- 52.123.252.203
- 4.230.171.124
- 172.215.188.232
- 52.110.12.45
- 52.110.12.38
- 72.153.5.141
- 52.148.114.188
- 52.110.12.30
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report