Loading ...

Play interactive tourEdit tour

Windows Analysis Report https://www.viewsonlines.com/newdocument

Overview

General Information

Sample URL:https://www.viewsonlines.com/newdocument
Analysis ID:483333
Infos:

Most interesting Screenshot:

Detection

HTMLPhisher
Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Yara detected HtmlPhish10
HTML body contains low number of good links
Invalid T&C link found
No HTML title found
Form action URLs do not match main URL

Classification

Process Tree

  • System is w10x64
  • chrome.exe (PID: 4504 cmdline: 'C:\Program Files\Google\Chrome\Application\chrome.exe' --start-maximized --enable-automation 'https://www.viewsonlines.com/newdocument' MD5: C139654B5C1438A95B321BB01AD63EF6)
    • chrome.exe (PID: 4664 cmdline: 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1564,18038790886677034936,7889654499624387867,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1776 /prefetch:8 MD5: C139654B5C1438A95B321BB01AD63EF6)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

No Sigma rule has matched

Jbx Signature Overview

Click to jump to signature section

Show All Signature Results

Phishing:

barindex
Yara detected HtmlPhish10Show sources
Source: Yara matchFile source: 01598.4.pages.csv, type: HTML
Source: Yara matchFile source: 80899.8.pages.csv, type: HTML
Source: Yara matchFile source: 70292.10.pages.csv, type: HTML
Source: https://ashercummins.com/fil/Odrivex/index.phpHTTP Parser: Number of links: 0
Source: https://equilibriumdiet.com/fil/Odrivex/index.phpHTTP Parser: Number of links: 0
Source: https://ashercummins.com/fil/Odrivex/index.phpHTTP Parser: Invalid link: Privacy & Cookies
Source: https://equilibriumdiet.com/fil/Odrivex/index.phpHTTP Parser: Invalid link: Privacy & Cookies
Source: https://ashercummins.com/fil/Odrivex/index.phpHTTP Parser: HTML title missing
Source: https://www.webador.co.uk/HTTP Parser: HTML title missing
Source: https://equilibriumdiet.com/fil/Odrivex/index.phpHTTP Parser: HTML title missing
Source: https://www.webador.com/HTTP Parser: HTML title missing
Source: https://www.webador.co.uk/HTTP Parser: Form action: https://www.webador.com/v2/account/register co webador
Source: https://www.webador.co.uk/HTTP Parser: Form action: https://www.facebook.com/tr/ co facebook
Source: https://www.webador.com/HTTP Parser: Form action: https://www.facebook.com/tr/ webador facebook
Source: https://ashercummins.com/fil/Odrivex/index.phpHTTP Parser: No <meta name="author".. found
Source: https://www.webador.co.uk/HTTP Parser: No <meta name="author".. found
Source: https://equilibriumdiet.com/fil/Odrivex/index.phpHTTP Parser: No <meta name="author".. found
Source: https://www.webador.com/HTTP Parser: No <meta name="author".. found
Source: https://ashercummins.com/fil/Odrivex/index.phpHTTP Parser: No <meta name="copyright".. found
Source: https://www.webador.co.uk/HTTP Parser: No <meta name="copyright".. found
Source: https://equilibriumdiet.com/fil/Odrivex/index.phpHTTP Parser: No <meta name="copyright".. found
Source: https://www.webador.com/HTTP Parser: No <meta name="copyright".. found
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\DictionariesJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdicJump to behavior
Source: unknownHTTPS traffic detected: 34.120.151.89:443 -> 192.168.2.7:49778 version: TLS 1.2