Analysis Report https://discovercommunitynetwork.com/mcief/FBG

Overview

General Information

Sample URL: https://discovercommunitynetwork.com/mcief/FBG
Analysis ID: 432783
Infos:

Most interesting Screenshot:

Detection

HTMLPhisher
Score: 88
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Antivirus detection for dropped file
Phishing site detected (based on shot template match)
Yara detected HtmlPhish7
Phishing site detected (based on image similarity)
Phishing site detected (based on logo template match)
HTML body contains low number of good links
HTML title does not match URL
Invalid T&C link found

Classification

AV Detection:

barindex
Antivirus / Scanner detection for submitted sample
Source: https://discovercommunitynetwork.com/mcief/FBG SlashNext: detection malicious, Label: Fake Login Page type: Phishing & Social usering
Antivirus detection for URL or domain
Source: https://discovercommunitynetwork.com/mcief/FBG/microsoft.php SlashNext: Label: Fake Login Page type: Phishing & Social usering
Source: https://discovercommunitynetwork.com/mcief/FBG/ SlashNext: Label: Fake Login Page type: Phishing & Social usering
Source: https://discovercommunitynetwork.com/mcief/FBG/webmail.php SlashNext: Label: Fake Login Page type: Phishing & Social usering
Source: https://discovercommunitynetwork.com/mcief/FBG/office.php SlashNext: Label: Fake Login Page type: Phishing & Social usering
Antivirus detection for dropped file
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\FBG[1].htm Avira: detection malicious, Label: HTML/Infected.WebPage.Gen2

Phishing:

barindex
Phishing site detected (based on shot template match)
Source: https://discovercommunitynetwork.com/mcief/FBG/ Matcher: Template: onedrive matched
Yara detected HtmlPhish7
Source: Yara match File source: 767668.pages.csv, type: HTML
Source: Yara match File source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\FBG[1].htm, type: DROPPED
Phishing site detected (based on image similarity)
Source: https://discovercommunitynetwork.com/mcief/FBG/images/Onedrive-logo.png Matcher: Found strong image similarity, brand: Microsoft Jump to dropped file
Phishing site detected (based on logo template match)
Source: https://discovercommunitynetwork.com/mcief/FBG/microsoft.php Matcher: Template: microsoft matched
Source: https://discovercommunitynetwork.com/mcief/FBG/office.php Matcher: Template: office matched
HTML body contains low number of good links
Source: https://discovercommunitynetwork.com/mcief/FBG/microsoft.php HTTP Parser: Number of links: 0
Source: https://discovercommunitynetwork.com/mcief/FBG/microsoft.php HTTP Parser: Number of links: 0
Source: https://discovercommunitynetwork.com/mcief/FBG/webmail.php HTTP Parser: Number of links: 0
Source: https://discovercommunitynetwork.com/mcief/FBG/webmail.php HTTP Parser: Number of links: 0
Source: https://discovercommunitynetwork.com/mcief/FBG/office.php HTTP Parser: Number of links: 1
Source: https://discovercommunitynetwork.com/mcief/FBG/office.php HTTP Parser: Number of links: 1
HTML title does not match URL
Source: https://discovercommunitynetwork.com/mcief/FBG/microsoft.php HTTP Parser: Title: Sign in to your Microsoft account does not match URL
Source: https://discovercommunitynetwork.com/mcief/FBG/microsoft.php HTTP Parser: Title: Sign in to your Microsoft account does not match URL
Source: https://discovercommunitynetwork.com/mcief/FBG/webmail.php HTTP Parser: Title: One Drive does not match URL
Source: https://discovercommunitynetwork.com/mcief/FBG/webmail.php HTTP Parser: Title: One Drive does not match URL
Source: https://discovercommunitynetwork.com/mcief/FBG/office.php HTTP Parser: Title: One Drive does not match URL
Source: https://discovercommunitynetwork.com/mcief/FBG/office.php HTTP Parser: Title: One Drive does not match URL
Invalid T&C link found
Source: https://discovercommunitynetwork.com/mcief/FBG/office.php HTTP Parser: Invalid link: Terms
Source: https://discovercommunitynetwork.com/mcief/FBG/office.php HTTP Parser: Invalid link: Privacy & Cookies
Source: https://discovercommunitynetwork.com/mcief/FBG/office.php HTTP Parser: Invalid link: Terms
Source: https://discovercommunitynetwork.com/mcief/FBG/office.php HTTP Parser: Invalid link: Privacy & Cookies
Source: https://discovercommunitynetwork.com/mcief/FBG/microsoft.php HTTP Parser: No <meta name="author".. found
Source: https://discovercommunitynetwork.com/mcief/FBG/microsoft.php HTTP Parser: No <meta name="author".. found
Source: https://discovercommunitynetwork.com/mcief/FBG/webmail.php HTTP Parser: No <meta name="author".. found
Source: https://discovercommunitynetwork.com/mcief/FBG/webmail.php HTTP Parser: No <meta name="author".. found
Source: https://discovercommunitynetwork.com/mcief/FBG/office.php HTTP Parser: No <meta name="author".. found
Source: https://discovercommunitynetwork.com/mcief/FBG/office.php HTTP Parser: No <meta name="author".. found
Source: https://discovercommunitynetwork.com/mcief/FBG/microsoft.php HTTP Parser: No <meta name="copyright".. found
Source: https://discovercommunitynetwork.com/mcief/FBG/microsoft.php HTTP Parser: No <meta name="copyright".. found
Source: https://discovercommunitynetwork.com/mcief/FBG/webmail.php HTTP Parser: No <meta name="copyright".. found
Source: https://discovercommunitynetwork.com/mcief/FBG/webmail.php HTTP Parser: No <meta name="copyright".. found
Source: https://discovercommunitynetwork.com/mcief/FBG/office.php HTTP Parser: No <meta name="copyright".. found
Source: https://discovercommunitynetwork.com/mcief/FBG/office.php HTTP Parser: No <meta name="copyright".. found
Source: C:\Program Files (x86)\Internet Explorer\iexplore.exe File opened: C:\Program Files (x86)\Java\jre1.8.0_211\bin\msvcr100.dll Jump to behavior
Source: unknown HTTPS traffic detected: 77.79.239.202:443 -> 192.168.2.6:49720 version: TLS 1.2
Source: unknown HTTPS traffic detected: 77.79.239.202:443 -> 192.168.2.6:49721 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.16.19.94:443 -> 192.168.2.6:49726 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.16.19.94:443 -> 192.168.2.6:49725 version: TLS 1.2
Source: unknown HTTPS traffic detected: 77.79.239.202:443 -> 192.168.2.6:49743 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.18.10.207:443 -> 192.168.2.6:49746 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.18.10.207:443 -> 192.168.2.6:49744 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.18.10.207:443 -> 192.168.2.6:49745 version: TLS 1.2
Source: unknown DNS traffic detected: queries for: discovercommunitynetwork.com
Source: fontawesome-webfont[1].eot.3.dr, font-awesome.min[1].css.3.dr String found in binary or memory: http://fontawesome.io
Source: font-awesome.min[1].css.3.dr String found in binary or memory: http://fontawesome.io/license
Source: fontawesome-webfont[1].eot.3.dr String found in binary or memory: http://fontawesome.io/license/
Source: fontawesome-webfont[1].eot.3.dr String found in binary or memory: http://fontawesome.iohttp://fontawesome.iohttp://fontawesome.io/license/http://fontawesome.io/licens
Source: FBG[1].htm0.3.dr String found in binary or memory: https://cdnjs.cloudflare.com/ajax/libs/tether/1.4.0/js/tether.min.js
Source: FBG[1].htm0.3.dr, microsoft[1].htm.3.dr String found in binary or memory: https://code.jquery.com/jquery-3.1.1.slim.min.js
Source: ~DF6E29A9E8804300A7.TMP.2.dr, {6D04534C-CA56-11EB-90E5-ECF4BB2D2496}.dat.2.dr String found in binary or memory: https://discovercommunitynetwork.com/mcief/FBG/
Source: {6D04534C-CA56-11EB-90E5-ECF4BB2D2496}.dat.2.dr String found in binary or memory: https://discovercommunitynetwork.com/mcief/FBG/Root
Source: {6D04534C-CA56-11EB-90E5-ECF4BB2D2496}.dat.2.dr String found in binary or memory: https://discovercommunitynetwork.com/mcief/FBG/itynetwork.com/mcief/FBG/microsok.com/mcief/FBG/
Source: {6D04534C-CA56-11EB-90E5-ECF4BB2D2496}.dat.2.dr String found in binary or memory: https://discovercommunitynetwork.com/mcief/FBG/itynetwork.com/mcief/FBG/office.k.com/mcief/FBG/
Source: {6D04534C-CA56-11EB-90E5-ECF4BB2D2496}.dat.2.dr String found in binary or memory: https://discovercommunitynetwork.com/mcief/FBG/itynetwork.com/mcief/FBG/webmailk.com/mcief/FBG/
Source: {6D04534C-CA56-11EB-90E5-ECF4BB2D2496}.dat.2.dr String found in binary or memory: https://discovercommunitynetwork.com/mcief/FBG/k.com/mcief/FBG/
Source: ~DF6E29A9E8804300A7.TMP.2.dr String found in binary or memory: https://discovercommunitynetwork.com/mcief/FBG/microsoft.php
Source: ~DF6E29A9E8804300A7.TMP.2.dr String found in binary or memory: https://discovercommunitynetwork.com/mcief/FBG/microsoft.phpBSign
Source: ~DF6E29A9E8804300A7.TMP.2.dr String found in binary or memory: https://discovercommunitynetwork.com/mcief/FBG/office.php
Source: ~DF6E29A9E8804300A7.TMP.2.dr String found in binary or memory: https://discovercommunitynetwork.com/mcief/FBG/office.phpwork.com/mcief/FBG/office.php
Source: ~DF6E29A9E8804300A7.TMP.2.dr String found in binary or memory: https://discovercommunitynetwork.com/mcief/FBG/webmail.php
Source: ~DF6E29A9E8804300A7.TMP.2.dr String found in binary or memory: https://discovercommunitynetwork.com/mcief/FBG/webmail.php://discovercommunitynetwork.com/mcief/FBG/
Source: ~DF6E29A9E8804300A7.TMP.2.dr String found in binary or memory: https://discovercommunitynetwork.com/mcief/FBG/webmail.phpv
Source: style[1].css.3.dr String found in binary or memory: https://fonts.googleapis.com/css?family=Open
Source: css[1].css.3.dr String found in binary or memory: https://fonts.gstatic.com/s/opensans/v20/mem5YaGs126MiZpBA-UN7rgOUuhv.woff)
Source: css[1].css.3.dr String found in binary or memory: https://fonts.gstatic.com/s/opensans/v20/mem5YaGs126MiZpBA-UN8rsOUuhv.woff)
Source: css[1].css.3.dr String found in binary or memory: https://fonts.gstatic.com/s/opensans/v20/mem5YaGs126MiZpBA-UN_r8OUuhv.woff)
Source: css[1].css.3.dr String found in binary or memory: https://fonts.gstatic.com/s/opensans/v20/mem5YaGs126MiZpBA-UNirkOUuhv.woff)
Source: css[1].css.3.dr String found in binary or memory: https://fonts.gstatic.com/s/opensans/v20/mem6YaGs126MiZpBA-UFUK0Zdcs.woff)
Source: css[1].css.3.dr String found in binary or memory: https://fonts.gstatic.com/s/opensans/v20/mem8YaGs126MiZpBA-UFVZ0d.woff)
Source: css[1].css.3.dr String found in binary or memory: https://fonts.gstatic.com/s/opensans/v20/memnYaGs126MiZpBA-UFUKW-U9hrIqU.woff)
Source: css[1].css.3.dr String found in binary or memory: https://fonts.gstatic.com/s/opensans/v20/memnYaGs126MiZpBA-UFUKWiUNhrIqU.woff)
Source: css[1].css.3.dr String found in binary or memory: https://fonts.gstatic.com/s/opensans/v20/memnYaGs126MiZpBA-UFUKWyV9hrIqU.woff)
Source: css[1].css.3.dr String found in binary or memory: https://fonts.gstatic.com/s/opensans/v20/memnYaGs126MiZpBA-UFUKXGUdhrIqU.woff)
Source: bootstrap.min[1].css.3.dr, bootstrap.min[1].css0.3.dr, bootstrap.min[1].js.3.dr String found in binary or memory: https://getbootstrap.com)
Source: bootstrap.min[1].css.3.dr, bootstrap.min[1].js.3.dr String found in binary or memory: https://github.com/twbs/bootstrap/blob/master/LICENSE)
Source: bootstrap.min[1].js.3.dr, bootstrap.min[1].js0.3.dr String found in binary or memory: https://github.com/twbs/bootstrap/graphs/contributors)
Source: office[1].htm.3.dr String found in binary or memory: https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0-alpha.6/css/bootstrap.min.css
Source: office[1].htm.3.dr String found in binary or memory: https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0-alpha.6/js/bootstrap.min.js
Source: microsoft[1].htm.3.dr String found in binary or memory: https://maxcdn.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.css
Source: microsoft[1].htm.3.dr String found in binary or memory: https://signup.live.com
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49744
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49721
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49743
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49720
Source: unknown Network traffic detected: HTTP traffic on port 49726 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49725 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49743 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49746 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49721 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49745 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49720 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49744 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49726
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49725
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49746
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49745
Source: unknown HTTPS traffic detected: 77.79.239.202:443 -> 192.168.2.6:49720 version: TLS 1.2
Source: unknown HTTPS traffic detected: 77.79.239.202:443 -> 192.168.2.6:49721 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.16.19.94:443 -> 192.168.2.6:49726 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.16.19.94:443 -> 192.168.2.6:49725 version: TLS 1.2
Source: unknown HTTPS traffic detected: 77.79.239.202:443 -> 192.168.2.6:49743 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.18.10.207:443 -> 192.168.2.6:49746 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.18.10.207:443 -> 192.168.2.6:49744 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.18.10.207:443 -> 192.168.2.6:49745 version: TLS 1.2
Source: classification engine Classification label: mal88.phis.win@3/42@5/4
Source: C:\Program Files\internet explorer\iexplore.exe File created: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{6D04534A-CA56-11EB-90E5-ECF4BB2D2496}.dat Jump to behavior
Source: C:\Program Files\internet explorer\iexplore.exe File created: C:\Users\user\AppData\Local\Temp\~DF8F906952B71A6755.TMP Jump to behavior
Source: C:\Program Files\internet explorer\iexplore.exe File read: C:\Users\desktop.ini Jump to behavior
Source: unknown Process created: C:\Program Files\internet explorer\iexplore.exe 'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
Source: C:\Program Files\internet explorer\iexplore.exe Process created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:4644 CREDAT:17410 /prefetch:2
Source: C:\Program Files\internet explorer\iexplore.exe Process created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:4644 CREDAT:17410 /prefetch:2 Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Internet Explorer\iexplore.exe File opened: C:\Program Files (x86)\Java\jre1.8.0_211\bin\msvcr100.dll Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs