Edit tour
Windows
Analysis Report
https://thegreenid.com/fonts/sharepoint3/?e=SmFtZXNzQGNwZXF1aXR5LmNvbQ==
Overview
General Information
Detection
HTMLPhisher
Score: | 72 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Yara detected HtmlPhish10
Antivirus detection for URL or domain
Phishing site detected (based on shot match)
Found C&C like URL pattern
Phishing site detected (based on logo match)
Detected hidden input values containing email addresses (often used in phishing pages)
Invalid 'forgot password' link found
HTML body contains password input but no form action
HTML body contains low number of good links
HTML title does not match URL
Classification
- System is w10x64_ra
- chrome.exe (PID: 2868 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t https:// thegreenid .com/fonts /sharepoin t3/?e=SmFt ZXNzQGNwZX F1aXR5LmNv bQ== MD5: 7BC7B4AEDC055BB02BCB52710132E9E1) - chrome.exe (PID: 3688 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2080 --fi eld-trial- handle=184 4,i,610156 3323010581 969,156385 5470218929 572,131072 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionTarget Prediction /prefetch :8 MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
- cleanup
⊘No configs have been found
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_HtmlPhish_10 | Yara detected HtmlPhish_10 | Joe Security | ||
JoeSecurity_HtmlPhish_10 | Yara detected HtmlPhish_10 | Joe Security |
⊘No Sigma rule has matched
⊘No Snort rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Phishing |
---|
Source: | File source: | ||
Source: | File source: |
Source: | Matcher: | ||
Source: | Matcher: |
Source: |