Windows
Analysis Report
https://1drv.ms:443/o/s!BDUkX1Fbp6_igwpBxnZTcbnBB5zq?e=90f04oI-vEKlpr0bwyVv1w&at=9
Overview
General Information
Detection
HTMLPhisher
Score: | 80 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Phishing site detected (based on shot template match)
Yara detected HtmlPhish10
Antivirus detection for URL or domain
Yara detected HtmlPhish7
Phishing site detected (based on various OCR indicators)
Phishing site detected (based on image similarity)
No HTML title found
HTML body contains low number of good links
Classification
- System is w10x64
chrome.exe (PID: 4968 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" --sta rt-maximiz ed --enabl e-automati on "https: //1drv.ms: 443/o/s!BD UkX1Fbp6_i gwpBxnZTcb nBB5zq?e=9 0f04oI-vEK lpr0bwyVv1 w&at=9 MD5: C139654B5C1438A95B321BB01AD63EF6) chrome.exe (PID: 5740 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -field-tri al-handle= 1528,13177 7907994175 37543,1802 8638101351 105962,131 072 --lang =en-US --s ervice-san dbox-type= network -- enable-aud io-service -sandbox - -mojo-plat form-chann el-handle= 1920 /pref etch:8 MD5: C139654B5C1438A95B321BB01AD63EF6)
- cleanup
⊘No configs have been found
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_HtmlPhish_10 | Yara detected HtmlPhish_10 | Joe Security | ||
JoeSecurity_HtmlPhish_7 | Yara detected HtmlPhish_7 | Joe Security |
⊘No Sigma rule has matched
⊘No Snort rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | SlashNext: |
Phishing |
---|
Source: | Matcher: |
Source: | File source: |
Source: | File source: |
Source: | OCR Text: |