SUSPICIOUS — fa39fa92fe930cfe0decfb81593a20ee994f95084e4efa49e81b75588b1ff43a
SUSPICIOUS — fa39fa92fe930cfe0decfb81593a20ee994f95084e4efa49e81b75588b1ff43a is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 1 of 50 detection engines flagged it.
Identification
- SHA-256:
fa39fa92fe930cfe0decfb81593a20ee994f95084e4efa49e81b75588b1ff43a - SHA-1:
bd841c061317d201796d070ef1d6146a95afca7c - MD5:
db902797266f7efb061f37f24146b06d - ssdeep:
1536:/KIRIOITIwIgIiKZgNDfIwIGI5IVJ7SqIRIOITIwIgIiKZgNDfIwIGI5IVJ7S47r:A7TImBaewP1k3AHwCm7FDWS1L - TLSH:
T1283B0A82B9A2C43117970E0293B88C5434EEE91B0B99DF86D5B89FD0B4B9E60704D5F7 - Submitted as: fa39fa92fe930cfe0decfb81593a20ee994f95084e4efa49e81b75588b1ff43a
- File type: html · Size: 111483 bytes
- Verdict: suspicious (54/100)
Detections (1 of 50 engines)
- Microsoft Defender: Trojan:Script/Wacatac.B!ml
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: http://ogp.me/ns/fb#, http://i.ytimg.com/vi/Ze2kpOZx_kU/hqdefault.jpg, http://s2.dmcdn.net/P3rVR/280x157-Rru.jpg - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://ogp.me/ns/fb#
- http://i.ytimg.com/vi/Ze2kpOZx_kU/hqdefault.jpg
- http://s2.dmcdn.net/P3rVR/280x157-Rru.jpg
- http://thehdroom.com/wp-content/uploads/2011/02/8363o1.jpg
- http://s2.dmcdn.net/Nwy-b/526x297-6XQ.jpg
- http://yle.fi/aihe/sites/aihe/files/migrated/elavaarkisto/kuvat/2013/img100780-previewImage.jpg
- http://im.mtv.fi/image/5283284/landscape16_9/1024/576/6a3d112ad0b8cc7b4d53a5871a4bc6dc/OH/mustekala.jpg
- http://www.hs.fi/webkuva/taysi/700/1475728227675?ts=835
- http://static-sls.smf.aws.sanomacloud.net/cosmopolitan.fi/s3fs-public/styles/medium_main_image_no_upscale/public/wysiwyg_images/mvphotos-0275797008.jpg?itok=FJN5gHrK
- http://www.katiska.info/wp-content/uploads/2015/11/rusetti-300x300.png
- http://clubpenguinprograms.com/wp-content/uploads/2016/06/State-Of-Grace.jpg
- http://filebrands.weebly.com/
- https://ajax.googleapis.com/ajax/libs/jquery/1.8.3/jquery.min.js
- http://filebrands.weebly.com/blog/a-street-cat-named-bob-2016-watch-trailer-online
- http://filebrands.weebly.com/blog/a-street-cat-named-bob-2016-watch-trailer-online#comments
- https://ajax.googleapis.com/ajax/libs/jquery/3.1.0/jquery.min.js
- http://filebrands.weebly.com/1/post/2016/12/a-street-cat-named-bob-2016-watch-trailer-online.html
- http://twitter.com/share?url=http://filebrands.weebly.com/1/post/2016/12/a-street-cat-named-bob-2016-watch-trailer-online.html
- http://filebrands.weebly.com/blog/online-watch-1080p-movie-2016-star-wars-rogue-one
- http://filebrands.weebly.com/blog/online-watch-1080p-movie-2016-star-wars-rogue-one#comments
- http://filebrands.weebly.com/1/post/2016/12/online-watch-1080p-movie-2016-star-wars-rogue-one.html
- http://twitter.com/share?url=http://filebrands.weebly.com/1/post/2016/12/online-watch-1080p-movie-2016-star-wars-rogue-one.html
- http://filebrands.weebly.com/blog/miksi-hn
- http://filebrands.weebly.com/blog/miksi-hn#comments
- http://filebrands.weebly.com/1/post/2016/12/miksi-hn.html
Embedded domains
- ogp.me
- i.ytimg.com
- s2.dmcdn.net
- thehdroom.com
- yle.fi
- im.mtv.fi
- www.hs.fi
- static-sls.smf.aws.sanomacloud.net
- cosmopolitan.fi
- www.katiska.info
- clubpenguinprograms.com
- filebrands.weebly.com
- cdn2.editmysite.com
- fonts.googleapis.com
- cdn1.editmysite.com
- ajax.googleapis.com
- www.weebly.com
- billboard.biz
- twitter.com
- highquality.co
- fr-telecharger-online.com
- www.wbab.com
- static.rogerebert.com
- photos.laineygossip.com
- 1f5ad49-trailerloop-production.s3.amazonaws.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report