Windows Analysis Report
https://bidproposalinvite.ucraft.site/

Overview

General Information

Sample URL: https://bidproposalinvite.ucraft.site/
Analysis ID: 562468

Detection

HTMLPhisher
Score: 60
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Yara detected HtmlPhish7
Yara detected HtmlPhish10
Phishing site detected (based on image similarity)
HTML body contains low number of good links
No HTML title found

Classification

Phishing

barindex
Source: Yara match File source: 07755.1.pages.csv, type: HTML
Source: Yara match File source: 07755.1.pages.csv, type: HTML
Source: https://taeappliances.space/schl/index.php Matcher: Found strong image similarity, brand: Microsoft image: 07755.1.img.2.gfk.csv C3FC46C5799C76F9107504028F39190F
Source: https://taeappliances.space/schl/index.php Matcher: Found strong image similarity, brand: Microsoft image: 07755.1.img.3.gfk.csv FE22440D79FFA34950F512EF4A718B2A
Source: https://taeappliances.space/schl/index.php Matcher: Found strong image similarity, brand: Microsoft image: 07755.1.img.2.gfk.csv C3FC46C5799C76F9107504028F39190F
Source: https://taeappliances.space/schl/index.php Matcher: Found strong image similarity, brand: Microsoft image: 07755.1.img.3.gfk.csv FE22440D79FFA34950F512EF4A718B2A
Source: https://taeappliances.space/schl/index.php Matcher: Found strong image similarity, brand: Microsoft image: 07755.1.img.2.gfk.csv C3FC46C5799C76F9107504028F39190F
Source: https://taeappliances.space/schl/index.php Matcher: Found strong image similarity, brand: Microsoft image: 07755.1.img.3.gfk.csv FE22440D79FFA34950F512EF4A718B2A
Source: https://taeappliances.space/schl/index.php Matcher: Found strong image similarity, brand: Microsoft image: 07755.1.img.2.gfk.csv C3FC46C5799C76F9107504028F39190F
Source: https://taeappliances.space/schl/index.php Matcher: Found strong image similarity, brand: Microsoft image: 07755.1.img.3.gfk.csv FE22440D79FFA34950F512EF4A718B2A
Source: https://taeappliances.space/schl/index.php Matcher: Found strong image similarity, brand: Microsoft image: 07755.1.img.2.gfk.csv C3FC46C5799C76F9107504028F39190F
Source: https://taeappliances.space/schl/index.php Matcher: Found strong image similarity, brand: Microsoft image: 07755.1.img.3.gfk.csv FE22440D79FFA34950F512EF4A718B2A
Source: https://taeappliances.space/schl/index.php Matcher: Found strong image similarity, brand: Microsoft image: 07755.1.img.2.gfk.csv C3FC46C5799C76F9107504028F39190F
Source: https://taeappliances.space/schl/index.php Matcher: Found strong image similarity, brand: Microsoft image: 07755.1.img.3.gfk.csv FE22440D79FFA34950F512EF4A718B2A
Source: https://taeappliances.space/schl/index.php Matcher: Found strong image similarity, brand: Microsoft image: 07755.1.img.2.gfk.csv C3FC46C5799C76F9107504028F39190F
Source: https://taeappliances.space/schl/index.php Matcher: Found strong image similarity, brand: Microsoft image: 07755.1.img.3.gfk.csv FE22440D79FFA34950F512EF4A718B2A
Source: https://taeappliances.space/schl/index.php Matcher: Found strong image similarity, brand: Microsoft image: 07755.1.img.2.gfk.csv C3FC46C5799C76F9107504028F39190F
Source: https://taeappliances.space/schl/index.php Matcher: Found strong image similarity, brand: Microsoft image: 07755.1.img.3.gfk.csv FE22440D79FFA34950F512EF4A718B2A
Source: https://taeappliances.space/schl/index.php Matcher: Found strong image similarity, brand: Microsoft image: 07755.1.img.2.gfk.csv C3FC46C5799C76F9107504028F39190F
Source: https://taeappliances.space/schl/index.php Matcher: Found strong image similarity, brand: Microsoft image: 07755.1.img.3.gfk.csv FE22440D79FFA34950F512EF4A718B2A
Source: https://taeappliances.space/schl/index.php HTTP Parser: Number of links: 0
Source: https://taeappliances.space/schl/index.php HTTP Parser: Number of links: 0
Source: https://taeappliances.space/schl/index.php HTTP Parser: HTML title missing
Source: https://taeappliances.space/schl/index.php HTTP Parser: HTML title missing
Source: https://taeappliances.space/schl/index.php HTTP Parser: No <meta name="author".. found
Source: https://taeappliances.space/schl/index.php HTTP Parser: No <meta name="author".. found
Source: https://taeappliances.space/schl/index.php HTTP Parser: No <meta name="copyright".. found
Source: https://taeappliances.space/schl/index.php HTTP Parser: No <meta name="copyright".. found
Source: unknown HTTPS traffic detected: 104.21.45.175:443 -> 192.168.2.3:52438 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.45.175:443 -> 192.168.2.3:52439 version: TLS 1.2
Source: unknown HTTPS traffic detected: 161.97.110.227:443 -> 192.168.2.3:52265 version: TLS 1.2
Source: unknown HTTPS traffic detected: 161.97.110.227:443 -> 192.168.2.3:52264 version: TLS 1.2
Source: chrome.exe Memory has grown: Private usage: 0MB later: 26MB
Source: unknown DNS traffic detected: queries for: clients2.google.com
Source: unknown Network traffic detected: HTTP traffic on port 63396 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52439
Source: unknown Network traffic detected: HTTP traffic on port 52269 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52438
Source: unknown Network traffic detected: HTTP traffic on port 52265 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50252
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50131
Source: unknown Network traffic detected: HTTP traffic on port 59894 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57803
Source: unknown Network traffic detected: HTTP traffic on port 56868 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52439 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50973
Source: unknown Network traffic detected: HTTP traffic on port 64333 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58988 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50131 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54119 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 60234 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64333
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55759
Source: unknown Network traffic detected: HTTP traffic on port 52266 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52440 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 62134 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53380 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52440
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55835
Source: unknown Network traffic detected: HTTP traffic on port 61959 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58988
Source: unknown Network traffic detected: HTTP traffic on port 52344 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58174 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53380
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53385
Source: unknown Network traffic detected: HTTP traffic on port 50973 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50925 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61959
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56170
Source: unknown Network traffic detected: HTTP traffic on port 50252 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52376 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58887 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 55835 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52267 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52376
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53266
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54119
Source: unknown Network traffic detected: HTTP traffic on port 55617 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 59616 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53385 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 60234
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 59894
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 62373
Source: unknown Network traffic detected: HTTP traffic on port 52264 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57803 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 62134
Source: unknown Network traffic detected: HTTP traffic on port 62373 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54325 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56170 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55617
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50925
Source: unknown Network traffic detected: HTTP traffic on port 52268 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52266
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 59616
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52344
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52267
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52264
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56868
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52265
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58887
Source: unknown Network traffic detected: HTTP traffic on port 52438 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53513 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53513
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52268
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54325
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52269
Source: unknown Network traffic detected: HTTP traffic on port 55759 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63639
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58174
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56593
Source: unknown Network traffic detected: HTTP traffic on port 63639 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63396
Source: unknown Network traffic detected: HTTP traffic on port 53266 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56593 -> 443
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown HTTPS traffic detected: 104.21.45.175:443 -> 192.168.2.3:52438 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.45.175:443 -> 192.168.2.3:52439 version: TLS 1.2
Source: unknown HTTPS traffic detected: 161.97.110.227:443 -> 192.168.2.3:52265 version: TLS 1.2
Source: unknown HTTPS traffic detected: 161.97.110.227:443 -> 192.168.2.3:52264 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\alfredo\AppData\Local\Temp\cae62aed-2c88-432b-b11d-59937ad13618.tmp
Source: classification engine Classification label: mal60.phis.win@32/171@13/184
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --enable-automation --single-argument https://bidproposalinvite.ucraft.site/
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1716,14055924472291308424,16679987354166750943,131072 --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2176 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1716,14055924472291308424,16679987354166750943,131072 --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2176 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-61F4DE16-1DBC.pma
Source: Window Recorder Window detected: More than 3 window changes detected
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs