Windows Analysis Report
https://dik.si/OB6x6

Overview

General Information

Sample URL: https://dik.si/OB6x6
Analysis ID: 635131

Detection

HTMLPhisher
Score: 80
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Antivirus / Scanner detection for submitted sample
Yara detected HtmlPhish7
Multi AV Scanner detection for domain / URL
Yara detected HtmlPhish10
Multi AV Scanner detection for submitted file
HTML body contains low number of good links
Suspicious form URL found
No HTML title found
Form action URLs do not match main URL

Classification

AV Detection

barindex
Source: https://dik.si/OB6x6 Avira URL Cloud: detection malicious, Label: phishing
Source: dik.si Virustotal: Detection: 5% Perma Link
Source: https://dik.si/OB6x6 Virustotal: Detection: 8% Perma Link

Phishing

barindex
Source: Yara match File source: 72168.0.pages.csv, type: HTML
Source: Yara match File source: 72168.0.pages.csv, type: HTML
Source: https://wealthprogress.mobilemoolah.net/wp-content/plugins/lgalmgawdq/aaa/adob/adob/ HTTP Parser: Number of links: 0
Source: https://wealthprogress.mobilemoolah.net/wp-content/plugins/lgalmgawdq/aaa/adob/adob/ HTTP Parser: Number of links: 0
Source: https://wealthprogress.mobilemoolah.net/wp-content/plugins/lgalmgawdq/aaa/adob/adob/ HTTP Parser: Form action: https://uudismelecopar.website/.65ft/a1zn.php
Source: https://wealthprogress.mobilemoolah.net/wp-content/plugins/lgalmgawdq/aaa/adob/adob/ HTTP Parser: Form action: https://uudismelecopar.website/.65ft/a1zn.php
Source: https://wealthprogress.mobilemoolah.net/wp-content/plugins/lgalmgawdq/aaa/adob/adob/ HTTP Parser: HTML title missing
Source: https://wealthprogress.mobilemoolah.net/wp-content/plugins/lgalmgawdq/aaa/adob/adob/ HTTP Parser: HTML title missing
Source: https://wealthprogress.mobilemoolah.net/wp-content/plugins/lgalmgawdq/aaa/adob/adob/ HTTP Parser: Form action: https://uudismelecopar.website/.65ft/a1zn.php mobilemoolah uudismelecopar
Source: https://wealthprogress.mobilemoolah.net/wp-content/plugins/lgalmgawdq/aaa/adob/adob/ HTTP Parser: Form action: https://uudismelecopar.website/.65ft/a1zn.php mobilemoolah uudismelecopar
Source: https://wealthprogress.mobilemoolah.net/wp-content/plugins/lgalmgawdq/aaa/adob/adob/ HTTP Parser: No <meta name="author".. found
Source: https://wealthprogress.mobilemoolah.net/wp-content/plugins/lgalmgawdq/aaa/adob/adob/ HTTP Parser: No <meta name="author".. found
Source: https://wealthprogress.mobilemoolah.net/wp-content/plugins/lgalmgawdq/aaa/adob/adob/ HTTP Parser: No <meta name="copyright".. found
Source: https://wealthprogress.mobilemoolah.net/wp-content/plugins/lgalmgawdq/aaa/adob/adob/ HTTP Parser: No <meta name="copyright".. found
Source: unknown HTTPS traffic detected: 64.227.108.223:443 -> 192.168.2.3:62205 version: TLS 1.2
Source: unknown HTTPS traffic detected: 64.227.108.223:443 -> 192.168.2.3:62206 version: TLS 1.2
Source: chrome.exe Memory has grown: Private usage: 5MB later: 10MB
Source: unknown DNS traffic detected: queries for: accounts.google.com
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50578
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50316
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57409
Source: unknown Network traffic detected: HTTP traffic on port 61763 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61994 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53129
Source: unknown Network traffic detected: HTTP traffic on port 60513 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55592
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 60935
Source: unknown Network traffic detected: HTTP traffic on port 58972 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65402 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 60513
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65402
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61763
Source: unknown Network traffic detected: HTTP traffic on port 62205 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50578 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 60935 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57409 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 59317 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50316 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52881
Source: unknown Network traffic detected: HTTP traffic on port 53129 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52881 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50367
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 59317
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50268
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 62205
Source: unknown Network traffic detected: HTTP traffic on port 62206 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 55592 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 59062 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 62206
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58972
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54771
Source: unknown Network traffic detected: HTTP traffic on port 50268 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 59062
Source: unknown Network traffic detected: HTTP traffic on port 50367 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54771 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61994
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.42
Source: unknown HTTPS traffic detected: 64.227.108.223:443 -> 192.168.2.3:62205 version: TLS 1.2
Source: unknown HTTPS traffic detected: 64.227.108.223:443 -> 192.168.2.3:62206 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\alfredo\AppData\Local\Temp\e6e382af-a0ac-45a7-bb4c-8b7026be385b.tmp
Source: classification engine Classification label: mal80.phis.win@27/80@10/211
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --enable-automation --single-argument https://dik.si/OB6x6
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1752,1225860649479586440,12493433813693861157,131072 --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2120 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1752,1225860649479586440,12493433813693861157,131072 --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2120 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-62914E16-199C.pma
Source: Window Recorder Window detected: More than 3 window changes detected
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs