Windows
Analysis Report
https://drive.google.com/uc?export=download&id=1mmXl38H2-j7e7hD_UJbEMMSnMTA0BtQV
Overview
General Information
Detection
HTMLPhisher
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Misleading page title found
Yara detected HtmlPhish10
Invalid 'forgot password' link found
None HTTPS page querying sensitive user data (password, username or email)
No HTML title found
HTML body contains low number of good links
Invalid T&C link found
Classification
- System is w10x64
chrome.exe (PID: 6136 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" --sta rt-maximiz ed --enabl e-automati on "https: //drive.go ogle.com/u c?export=d ownload&id =1mmXl38H2 -j7e7hD_UJ bEMMSnMTA0 BtQV MD5: C139654B5C1438A95B321BB01AD63EF6) chrome.exe (PID: 3648 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -field-tri al-handle= 1596,13766 7329608563 06384,1494 4723332545 166900,131 072 --lang =en-US --s ervice-san dbox-type= network -- enable-aud io-service -sandbox - -mojo-plat form-chann el-handle= 1936 /pref etch:8 MD5: C139654B5C1438A95B321BB01AD63EF6) chrome.exe (PID: 6912 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= quarantine .mojom.Qua rantine -- field-tria l-handle=1 596,137667 3296085630 6384,14944 7233325451 66900,1310 72 --lang= en-US --se rvice-sand box-type=n one --enab le-audio-s ervice-san dbox --moj o-platform -channel-h andle=4796 /prefetch :8 MD5: C139654B5C1438A95B321BB01AD63EF6)
- cleanup
⊘No configs have been found
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_HtmlPhish_10 | Yara detected HtmlPhish_10 | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_HtmlPhish_10 | Yara detected HtmlPhish_10 | Joe Security |
⊘No Sigma rule has matched
⊘No Snort rule has matched
Click to jump to signature section
Show All Signature Results
Phishing |
---|
Source: | Page Title: | ||
Source: | Page Title: |
Source: | File source: | ||
Source: | File source: |