Analysis Report https://yolotats.com/Borrower/Borrower's-details.shtml

Overview

General Information

Sample URL: https://yolotats.com/Borrower/Borrower's-details.shtml
Analysis ID: 412647
Infos:

Most interesting Screenshot:

Detection

HTMLPhisher
Score: 56
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Antivirus / Scanner detection for submitted sample
Yara detected HtmlPhish10
HTML body contains low number of good links
HTML title does not match URL
Suspicious form URL found

Classification

AV Detection:

barindex
Antivirus / Scanner detection for submitted sample
Source: https://yolotats.com/Borrower/Borrower's-details.shtml SlashNext: detection malicious, Label: Fake Login Page type: Phishing & Social Engineering

Phishing:

barindex
Yara detected HtmlPhish10
Source: Yara match File source: 22654.pages.csv, type: HTML
HTML body contains low number of good links
Source: https://yolotats.com/Borrower/Borrower's-details.shtml HTTP Parser: Number of links: 0
Source: https://yolotats.com/Borrower/Borrower's-details.shtml HTTP Parser: Number of links: 0
HTML title does not match URL
Source: https://yolotats.com/Borrower/Borrower's-details.shtml HTTP Parser: Title: First American Policy Inquiry Website does not match URL
Source: https://yolotats.com/Borrower/Borrower's-details.shtml HTTP Parser: Title: First American Policy Inquiry Website does not match URL
Suspicious form URL found
Source: https://yolotats.com/Borrower/Borrower's-details.shtml HTTP Parser: Form action: 0.php
Source: https://yolotats.com/Borrower/Borrower's-details.shtml HTTP Parser: Form action: 0.php
Source: https://yolotats.com/Borrower/Borrower's-details.shtml HTTP Parser: No <meta name="author".. found
Source: https://yolotats.com/Borrower/Borrower's-details.shtml HTTP Parser: No <meta name="author".. found
Source: https://yolotats.com/Borrower/Borrower's-details.shtml HTTP Parser: No <meta name="copyright".. found
Source: https://yolotats.com/Borrower/Borrower's-details.shtml HTTP Parser: No <meta name="copyright".. found
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic Jump to behavior
Source: unknown HTTPS traffic detected: 69.49.235.204:443 -> 192.168.2.5:49710 version: TLS 1.2
Source: unknown HTTPS traffic detected: 69.49.235.204:443 -> 192.168.2.5:49711 version: TLS 1.2
Source: unknown HTTPS traffic detected: 69.49.235.204:443 -> 192.168.2.5:49748 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.129.24.42:443 -> 192.168.2.5:49756 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.175.83.99:443 -> 192.168.2.5:49757 version: TLS 1.2
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.159.134
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.159.134
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.159.134
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.159.134
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.159.134
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.159.134
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.159.134
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.159.134
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.159.134
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.159.134
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.159.134
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.220.29
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.220.29
Source: unknown TCP traffic detected without corresponding DNS query: 23.57.81.29
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.220.29
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.220.29
Source: unknown DNS traffic detected: queries for: yolotats.com
Source: 77EC63BDA74BD0D0E0426DC8F8008506.1.dr String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
Source: manifest.json0.0.dr, 7b6f9a58-09a1-4ba0-b1ac-30b1a8005059.tmp.1.dr String found in binary or memory: https://accounts.google.com
Source: manifest.json0.0.dr, 7b6f9a58-09a1-4ba0-b1ac-30b1a8005059.tmp.1.dr String found in binary or memory: https://apis.google.com
Source: 7b6f9a58-09a1-4ba0-b1ac-30b1a8005059.tmp.1.dr String found in binary or memory: https://clients2.google.com
Source: manifest.json1.0.dr String found in binary or memory: https://clients2.google.com/service/update2/crx
Source: 7b6f9a58-09a1-4ba0-b1ac-30b1a8005059.tmp.1.dr String found in binary or memory: https://clients2.googleusercontent.com
Source: manifest.json0.0.dr String found in binary or memory: https://content.googleapis.com
Source: Reporting and NEL.1.dr String found in binary or memory: https://csp.withgoogle.com/csp/report-to/IdentityListAccountsHttp/external
Source: 7b6f9a58-09a1-4ba0-b1ac-30b1a8005059.tmp.1.dr, 533d441f-2c82-4fb7-b488-51a1d33de4c4.tmp.1.dr String found in binary or memory: https://dns.google
Source: manifest.json0.0.dr String found in binary or memory: https://feedback.googleusercontent.com
Source: 7b6f9a58-09a1-4ba0-b1ac-30b1a8005059.tmp.1.dr String found in binary or memory: https://fonts.googleapis.com
Source: manifest.json0.0.dr String found in binary or memory: https://fonts.googleapis.com;
Source: 7b6f9a58-09a1-4ba0-b1ac-30b1a8005059.tmp.1.dr String found in binary or memory: https://fonts.gstatic.com
Source: manifest.json0.0.dr String found in binary or memory: https://fonts.gstatic.com;
Source: manifest.json0.0.dr String found in binary or memory: https://hangouts.google.com/
Source: 7b6f9a58-09a1-4ba0-b1ac-30b1a8005059.tmp.1.dr String found in binary or memory: https://ogs.google.com
Source: manifest.json1.0.dr String found in binary or memory: https://payments.google.com/payments/v4/js/integrator.js
Source: manifest.json1.0.dr String found in binary or memory: https://sandbox.google.com/payments/v4/js/integrator.js
Source: 7b6f9a58-09a1-4ba0-b1ac-30b1a8005059.tmp.1.dr String found in binary or memory: https://ssl.gstatic.com
Source: messages.json41.0.dr String found in binary or memory: https://support.google.com/chromecast/answer/2998456
Source: messages.json41.0.dr String found in binary or memory: https://support.google.com/chromecast/troubleshooter/2995236
Source: 58c452aae925b73a_0.0.dr String found in binary or memory: https://www.google-analytics.com/analytics.js
Source: 080e5d32096294ef_0.0.dr String found in binary or memory: https://www.google-analytics.com/plugins/ua/linkid.js
Source: manifest.json0.0.dr, 7b6f9a58-09a1-4ba0-b1ac-30b1a8005059.tmp.1.dr String found in binary or memory: https://www.google.com
Source: manifest.json1.0.dr String found in binary or memory: https://www.google.com/
Source: manifest.json0.0.dr String found in binary or memory: https://www.google.com;
Source: 7b6f9a58-09a1-4ba0-b1ac-30b1a8005059.tmp.1.dr String found in binary or memory: https://www.googleapis.com
Source: manifest.json1.0.dr String found in binary or memory: https://www.googleapis.com/
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/calendar.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/cast-edu-messaging
Source: manifest.json1.0.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore
Source: manifest.json1.0.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/clouddevices
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/meetings
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/plus.peopleapi.readwrite
Source: manifest.json1.0.dr String found in binary or memory: https://www.googleapis.com/auth/sierra
Source: manifest.json1.0.dr String found in binary or memory: https://www.googleapis.com/auth/sierrasandbox
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/userinfo.email
Source: 7b6f9a58-09a1-4ba0-b1ac-30b1a8005059.tmp.1.dr String found in binary or memory: https://www.gstatic.com
Source: manifest.json0.0.dr String found in binary or memory: https://www.gstatic.com;
Source: 58c452aae925b73a_0.0.dr String found in binary or memory: https://yolotats.com/
Source: 080e5d32096294ef_0.0.dr String found in binary or memory: https://yolotats.com/-
Source: History.0.dr String found in binary or memory: https://yolotats.com/Borrower/Borrower
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49689
Source: unknown Network traffic detected: HTTP traffic on port 49710 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49758 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49687
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49720
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49742
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49680
Source: unknown Network traffic detected: HTTP traffic on port 49725 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49741 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49748 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49720 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49722 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49680 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49759
Source: unknown Network traffic detected: HTTP traffic on port 49759 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49757
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49756
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49711
Source: unknown Network traffic detected: HTTP traffic on port 49757 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49710
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49853
Source: unknown Network traffic detected: HTTP traffic on port 49711 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49740 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49742 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49723 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49689 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49687 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49681 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49748
Source: unknown Network traffic detected: HTTP traffic on port 49756 -> 443
Source: unknown HTTPS traffic detected: 69.49.235.204:443 -> 192.168.2.5:49710 version: TLS 1.2
Source: unknown HTTPS traffic detected: 69.49.235.204:443 -> 192.168.2.5:49711 version: TLS 1.2
Source: unknown HTTPS traffic detected: 69.49.235.204:443 -> 192.168.2.5:49748 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.129.24.42:443 -> 192.168.2.5:49756 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.175.83.99:443 -> 192.168.2.5:49757 version: TLS 1.2
Source: classification engine Classification label: mal56.phis.win@33/211@8/9
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-609C9FDB-424.pma Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Temp\7be03483-19c8-43d8-b5f2-304d3604e036.tmp Jump to behavior
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --start-maximized --enable-automation 'https://yolotats.com/Borrower/Borrower's-details.shtml'
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1704,1686343471565443222,3804912756075544807,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1752 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1704,1686343471565443222,3804912756075544807,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1752 /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Automated click: Next
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Automated click: agree
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Automated click: Next
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Automated click: Next
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Automated click: agree
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic Jump to behavior
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 412647 URL: https://yolotats.com/Borrow... Startdate: 12/05/2021 Architecture: WINDOWS Score: 56 13 www.maskeny.com 2->13 15 maskeny.com 2->15 17 2 other IPs or domains 2->17 31 Antivirus / Scanner detection for submitted sample 2->31 33 Yara detected HtmlPhish10 2->33 7 chrome.exe 13 501 2->7         started        signatures3 process4 dnsIp5 19 192.168.2.1 unknown unknown 7->19 21 192.168.2.5, 443, 49557, 49677 unknown unknown 7->21 23 239.255.255.250 unknown Reserved 7->23 10 chrome.exe 18 7->10         started        process6 dnsIp7 25 yolotats.com 69.49.235.204, 443, 49710, 49711 UNIFIEDLAYER-AS-1US United States 10->25 27 googlehosted.l.googleusercontent.com 216.58.212.129, 443, 49759 GOOGLEUS United States 10->27 29 6 other IPs or domains 10->29
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs

Contacted Public IPs

IP Domain Country Flag ASN ASN Name Malicious
104.129.24.42
gofirstam.com United States
8100 ASN-QUADRANET-GLOBALUS false
216.58.212.129
googlehosted.l.googleusercontent.com United States
15169 GOOGLEUS false
239.255.255.250
unknown Reserved
unknown unknown false
184.175.83.99
maskeny.com United States
7393 CYBERCONUS false
69.49.235.204
yolotats.com United States
46606 UNIFIEDLAYER-AS-1US false
69.87.16.180
insagent.firstam.com United States
13782 FAFCOUS false

Private

IP
192.168.2.1
192.168.2.5
127.0.0.1

Contacted Domains

Name IP Active
yolotats.com 69.49.235.204 true
gofirstam.com 104.129.24.42 true
insagent.firstam.com 69.87.16.180 true
googlehosted.l.googleusercontent.com 216.58.212.129 true
maskeny.com 184.175.83.99 true
clients2.googleusercontent.com unknown unknown
www.maskeny.com unknown unknown

Contacted URLs

Name Malicious Antivirus Detection Reputation
https://yolotats.com/Borrower/Borrower's-details.shtml true
    unknown