Windows
Analysis Report
https://tap-rt-prod1-t.campaign.adobe.com/r/?id=h9ecb88b,c1e96b3,69fe0fb&p1=zoom-meeting.top/scJF1SSXVzFB/zFBa2scJF17067/HkeS73tjSSXV1331248624633021?HkeS73tjSSXV1331248624633021=Yy5iYWtrZXJAbWVkaXJldmEubmw=
Overview
General Information
Detection
HTMLPhisher
Score: | 80 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus / Scanner detection for submitted sample
Phishing site detected (based on favicon image match)
Yara detected HtmlPhish10
Antivirus detection for URL or domain
Phishing site detected (based on logo match)
HTML page contains suspicious base64 encoded javascript
Queries the volume information (name, serial number etc) of a device
Tries to load missing DLLs
May sleep (evasive loops) to hinder dynamic analysis
Creates files inside the system directory
HTML body contains password input but no form action
HTML page contains hidden URLs or javascript code
Queries disk information (often used to detect virtual machines)
HTML body contains low number of good links
HTML title does not match URL
Classification
- System is w10x64
chrome.exe (PID: 2708 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" --sta rt-maximiz ed "about: blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) chrome.exe (PID: 2076 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2524 --fi eld-trial- handle=249 2,i,131059 6309166461 0280,11088 9049573032 96271,2621 44 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction / prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
svchost.exe (PID: 1868 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
chrome.exe (PID: 6468 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" "http s://tap-rt -prod1-t.c ampaign.ad obe.com/r/ ?id=h9ecb8 8b,c1e96b3 ,69fe0fb&p 1=zoom-mee ting.top/s cJF1SSXVzF B/zFBa2scJ F17067/Hke S73tjSSXV1 3312486246 33021?HkeS 73tjSSXV13 3124862463 3021=Yy5iY WtrZXJAbWV kaXJldmEub mw= MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
⊘No configs have been found
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_HtmlPhish_10 | Yara detected HtmlPhish_10 | Joe Security | ||
JoeSecurity_HtmlPhish_10 | Yara detected HtmlPhish_10 | Joe Security |
⊘No Sigma rule has matched
⊘No Snort rule has matched
- • AV Detection
- • Phishing
- • Compliance
- • Networking
- • System Summary
- • Malware Analysis System Evasion
- • Language, Device and Operating System Detection
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | SlashNext: |
Source: | Avira URL Cloud: |
Phishing |
---|
Source: | Matcher: | ||
Source: |