Source: https://csmcapitalccorp.com/ | Avira URL Cloud: detection malicious, Label: phishing |
Source: https://csmcapitalccorp.com/ | SlashNext: detection malicious, Label: Fake Login Page type: Phishing & Social Engineering |
Source: https://csmcapitalccorp.com/ | UrlScan: detection malicious, Label: phishing brand: sharepoint microsoft | Perma Link |
Source: https://csmcapitalccorp.com/s/?signin=d41d8cd98f00b204e9800998ecf8427e&auth=e6d1fb745bbfa3f6e65161cfc7b13522439ad123413fc691592314d502b00c3032efe62f | SlashNext: Label: Fake Login Page type: Phishing & Social Engineering |
Source: https://csmcapitalccorp.com/s/?signin=d41d8cd98f00b204e9800998ecf8427e&auth=e6d1fb745bbfa3f6e65161cf | Avira URL Cloud: Label: phishing |
Source: Yara match | File source: 035347.pages.csv, type: HTML |
Source: Yara match | File source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\s[1].htm, type: DROPPED |
Source: https://csmcapitalccorp.com/s/files/logo.png | Matcher: Found strong image similarity, brand: Microsoft | Jump to dropped file |
Source: https://csmcapitalccorp.com/s/?signin=d41d8cd98f00b204e9800998ecf8427e&auth=e6d1fb745bbfa3f6e65161cfc7b13522439ad123413fc691592314d502b00c3032efe62f | Matcher: Template: microsoft matched |
Source: https://csmcapitalccorp.com/s/?signin=d41d8cd98f00b204e9800998ecf8427e&auth=e6d1fb745bbfa3f6e65161cfc7b13522439ad123413fc691592314d502b00c3032efe62f | HTTP Parser: Number of links: 0 |
Source: https://csmcapitalccorp.com/s/?signin=d41d8cd98f00b204e9800998ecf8427e&auth=e6d1fb745bbfa3f6e65161cfc7b13522439ad123413fc691592314d502b00c3032efe62f | HTTP Parser: Number of links: 0 |
Source: https://csmcapitalccorp.com/s/?signin=d41d8cd98f00b204e9800998ecf8427e&auth=e6d1fb745bbfa3f6e65161cfc7b13522439ad123413fc691592314d502b00c3032efe62f | HTTP Parser: Title: Validation does not match URL |
Source: https://csmcapitalccorp.com/s/?signin=d41d8cd98f00b204e9800998ecf8427e&auth=e6d1fb745bbfa3f6e65161cfc7b13522439ad123413fc691592314d502b00c3032efe62f | HTTP Parser: Title: Validation does not match URL |
Source: https://csmcapitalccorp.com/s/?signin=d41d8cd98f00b204e9800998ecf8427e&auth=e6d1fb745bbfa3f6e65161cfc7b13522439ad123413fc691592314d502b00c3032efe62f | HTTP Parser: No <meta name="author".. found |
Source: https://csmcapitalccorp.com/s/?signin=d41d8cd98f00b204e9800998ecf8427e&auth=e6d1fb745bbfa3f6e65161cfc7b13522439ad123413fc691592314d502b00c3032efe62f | HTTP Parser: No <meta name="author".. found |
Source: https://csmcapitalccorp.com/s/?signin=d41d8cd98f00b204e9800998ecf8427e&auth=e6d1fb745bbfa3f6e65161cfc7b13522439ad123413fc691592314d502b00c3032efe62f | HTTP Parser: No <meta name="copyright".. found |
Source: https://csmcapitalccorp.com/s/?signin=d41d8cd98f00b204e9800998ecf8427e&auth=e6d1fb745bbfa3f6e65161cfc7b13522439ad123413fc691592314d502b00c3032efe62f | HTTP Parser: No <meta name="copyright".. found |
Source: C:\Program Files (x86)\Internet Explorer\iexplore.exe | File opened: C:\Program Files (x86)\Java\jre1.8.0_211\bin\msvcr100.dll | Jump to behavior |
Source: msapplication.xml0.1.dr | String found in binary or memory: <browserconfig><msapplication><config><site src="http://www.facebook.com/"/><date>0xf08fa6e5,0x01d72c28</date><accdate>0xf08fa6e5,0x01d72c28</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig> equals www.facebook.com (Facebook) |
Source: msapplication.xml0.1.dr | String found in binary or memory: <browserconfig><msapplication><config><site src="http://www.facebook.com/"/><date>0xf08fa6e5,0x01d72c28</date><accdate>0xf08fa6e5,0x01d72c28</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Facebook.url"/></tile></msapplication></browserconfig> equals www.facebook.com (Facebook) |
Source: msapplication.xml5.1.dr | String found in binary or memory: <browserconfig><msapplication><config><site src="http://www.twitter.com/"/><date>0xf0a05737,0x01d72c28</date><accdate>0xf0a05737,0x01d72c28</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig> equals www.twitter.com (Twitter) |
Source: msapplication.xml5.1.dr | String found in binary or memory: <browserconfig><msapplication><config><site src="http://www.twitter.com/"/><date>0xf0a05737,0x01d72c28</date><accdate>0xf0a05737,0x01d72c28</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Twitter.url"/></tile></msapplication></browserconfig> equals www.twitter.com (Twitter) |
Source: msapplication.xml7.1.dr | String found in binary or memory: <browserconfig><msapplication><config><site src="http://www.youtube.com/"/><date>0xf0a77eab,0x01d72c28</date><accdate>0xf0a77eab,0x01d72c28</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig> equals www.youtube.com (Youtube) |
Source: msapplication.xml7.1.dr | String found in binary or memory: <browserconfig><msapplication><config><site src="http://www.youtube.com/"/><date>0xf0a77eab,0x01d72c28</date><accdate>0xf0a77eab,0x01d72c28</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Youtube.url"/></tile></msapplication></browserconfig> equals www.youtube.com (Youtube) |
Source: unknown | DNS traffic detected: queries for: csmcapitalccorp.com |
Source: msapplication.xml.1.dr | String found in binary or memory: http://www.amazon.com/ |
Source: msapplication.xml1.1.dr | String found in binary or memory: http://www.google.com/ |
Source: msapplication.xml2.1.dr | String found in binary or memory: http://www.live.com/ |
Source: msapplication.xml3.1.dr | String found in binary or memory: http://www.nytimes.com/ |
Source: msapplication.xml4.1.dr | String found in binary or memory: http://www.reddit.com/ |
Source: msapplication.xml5.1.dr | String found in binary or memory: http://www.twitter.com/ |
Source: msapplication.xml6.1.dr | String found in binary or memory: http://www.wikipedia.com/ |
Source: msapplication.xml7.1.dr | String found in binary or memory: http://www.youtube.com/ |
Source: {1A95955A-981C-11EB-90EB-ECF4BBEA1588}.dat.1.dr, ~DF8F64FE653A1BED59.TMP.1.dr | String found in binary or memory: https://csmcapitalccorp.com/s/?signin=d41d8cd98f00b204e9800998ecf8427e&auth=e6d1fb745bbfa3f6e65161cf |
Source: css[1].css0.2.dr | String found in binary or memory: https://fonts.gstatic.com/s/opensans/v18/mem5YaGs126MiZpBA-UNirkOUuhv.woff) |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49742 |
Source: unknown | Network traffic detected: HTTP traffic on port 49726 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49725 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49724 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49742 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49726 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49725 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49724 |
Source: classification engine | Classification label: mal72.phis.win@3/21@2/1 |
Source: C:\Program Files\internet explorer\iexplore.exe | File created: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{1A959558-981C-11EB-90EB-ECF4BBEA1588}.dat | Jump to behavior |
Source: C:\Program Files\internet explorer\iexplore.exe | File created: C:\Users\user\AppData\Local\Temp\~DF74735D9205806B08.TMP | Jump to behavior |
Source: C:\Program Files\internet explorer\iexplore.exe | File read: C:\Users\desktop.ini | Jump to behavior |
Source: unknown | Process created: C:\Program Files\internet explorer\iexplore.exe 'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding | |
Source: C:\Program Files\internet explorer\iexplore.exe | Process created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:6004 CREDAT:17410 /prefetch:2 | |
Source: C:\Program Files\internet explorer\iexplore.exe | Process created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:6004 CREDAT:17410 /prefetch:2 | Jump to behavior |
Source: Window Recorder | Window detected: More than 3 window changes detected |
Source: C:\Program Files (x86)\Internet Explorer\iexplore.exe | File opened: C:\Program Files (x86)\Java\jre1.8.0_211\bin\msvcr100.dll | Jump to behavior |
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.