Windows Analysis Report
test@somewhere.com.html

Overview

General Information

Sample Name: test@somewhere.com.html
Analysis ID: 655631
MD5: 2d475c74396d3a17455856e03750e639
SHA1: 8be111091be27e9caa1902c9aa38e6469985dcaf
SHA256: 1dffbbe9eb7c804144f3fd8744cee452450d7c6bbf0209f258e7507c08d2ef6b
Infos:

Detection

HTMLPhisher
Score: 56
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Yara detected HtmlPhish44
Snort IDS alert for network traffic
HTML body contains low number of good links
None HTTPS page querying sensitive user data (password, username or email)
No HTML title found

Classification

Phishing

barindex
Source: Yara match File source: test@somewhere.com.html, type: SAMPLE
Source: file:///C:/Users/alfredo/Desktop/test@somewhere.com.html HTTP Parser: Number of links: 0
Source: file:///C:/Users/alfredo/Desktop/test@somewhere.com.html HTTP Parser: Number of links: 0
Source: file:///C:/Users/alfredo/Desktop/test@somewhere.com.html HTTP Parser: Has password / email / username input fields
Source: file:///C:/Users/alfredo/Desktop/test@somewhere.com.html HTTP Parser: Has password / email / username input fields
Source: file:///C:/Users/alfredo/Desktop/test@somewhere.com.html HTTP Parser: HTML title missing
Source: file:///C:/Users/alfredo/Desktop/test@somewhere.com.html HTTP Parser: HTML title missing
Source: file:///C:/Users/alfredo/Desktop/test@somewhere.com.html HTTP Parser: No <meta name="author".. found
Source: file:///C:/Users/alfredo/Desktop/test@somewhere.com.html HTTP Parser: No <meta name="author".. found
Source: file:///C:/Users/alfredo/Desktop/test@somewhere.com.html HTTP Parser: No <meta name="copyright".. found
Source: file:///C:/Users/alfredo/Desktop/test@somewhere.com.html HTTP Parser: No <meta name="copyright".. found
Source: chrome.exe Memory has grown: Private usage: 0MB later: 13MB

Networking

barindex
Source: Traffic Snort IDS: 2027757 ET DNS Query for .to TLD 192.168.2.3:52544 -> 1.1.1.1:53
Source: unknown DNS traffic detected: queries for: cdnjs.cloudflare.com
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54819
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56916
Source: unknown Network traffic detected: HTTP traffic on port 60760 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51463
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61949
Source: unknown Network traffic detected: HTTP traffic on port 56916 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57420 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50770
Source: unknown Network traffic detected: HTTP traffic on port 54819 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 59107
Source: unknown Network traffic detected: HTTP traffic on port 54892 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56512
Source: unknown Network traffic detected: HTTP traffic on port 49195 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52172 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57308 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50820
Source: unknown Network traffic detected: HTTP traffic on port 51009 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49453
Source: unknown Network traffic detected: HTTP traffic on port 61351 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63581
Source: unknown Network traffic detected: HTTP traffic on port 53750 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53462 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57830 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58873 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64317 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 51692 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57420
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64306
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58873
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58114
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53462
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52172
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52491
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61351
Source: unknown Network traffic detected: HTTP traffic on port 53543 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61949 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57548 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51009
Source: unknown Network traffic detected: HTTP traffic on port 59135 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 51463 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50124 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54290 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52491 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53543
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57548
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61609
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57308
Source: unknown Network traffic detected: HTTP traffic on port 64306 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 59135
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64317
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51130
Source: unknown Network traffic detected: HTTP traffic on port 56512 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61770 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49453 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58114 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 59107 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49195
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51692
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53750
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50124
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57830
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 60760
Source: unknown Network traffic detected: HTTP traffic on port 51130 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54892
Source: unknown Network traffic detected: HTTP traffic on port 50820 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63581 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61609 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61770
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54290
Source: unknown Network traffic detected: HTTP traffic on port 50770 -> 443
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: www.somewhere.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\alfredo\AppData\Local\Temp\37fd234e-c818-4886-beec-9e1baace1842.tmp
Source: classification engine Classification label: mal56.phis.winHTML@22/75@12/89
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --enable-automation --single-argument C:\Users\alfredo\Desktop\test@somewhere.com.html
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1728,15277383464472110615,3560837105709000163,131072 --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2108 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1728,15277383464472110615,3560837105709000163,131072 --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2108 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-62BF3CC7-994.pma
Source: Window Recorder Window detected: More than 3 window changes detected
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs