Edit tour
Windows
Analysis Report
https://us-west-2.protection.sophos.com/?d=intuit.com&u=aHR0cDovL2xpbmtzLm5vdGlmaWNhdGlvbi5pbnR1aXQuY29tL2xzL2NsaWNrP3Vwbj11MDAxLkh1OW5Ub0pMeHNKU1FSOFpIV244SWI3SmlrWUY2UE5YdjVWSy0yQkFmZVNwVkhQUk55LTJCRkR0Si0yQmhOVWZLWFR2ZXJvZnJLanZYVktINGJhNUtiVFgtMkJTNFhpZGQwY2hlRzhMd2JTdEVOU291TEdWSGRaTURZN0hlck0y
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Found HTTP page in a blob
Phishing site detected (based on OCR NLP Model)
Found iframes
HTML body contains low number of good links
HTML body contains password input but no form action
HTML page contains hidden URLs or javascript code
HTML title does not match URL
Stores files to the Windows start menu directory
Classification
- System is w10x64_ra
- chrome.exe (PID: 4508 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t https:// us-west-2. protection .sophos.co m/?d=intui t.com&u=aH R0cDovL2xp bmtzLm5vdG lmaWNhdGlv bi5pbnR1aX QuY29tL2xz L2NsaWNrP3 Vwbj11MDAx Lkh1OW5Ub0 pMeHNKU1FS OFpIV244SW I3SmlrWUY2 UE5YdjVWSy 0yQkFmZVNw VkhQUk55LT JCRkR0Si0y QmhOVWZLWF R2ZXJvZnJL anZYVktING JhNUtiVFgt MkJTNFhpZG QwY2hlRzhM d2JTdEVOU2 91TEdWSGRa TURZN0hlck 0yampVQ29G ZUk2Z203S2 R0ZjRWTEdl S1NFR0QtMk JMdEM5REpS Tnc2cEVNal NOTHdMVjZm LTJCLTJGTk RxZVR0d1pu dENvSlV2Mm tqbHk5bHhi Y2VzZ0NhWU JTNHhUUjR2 clhvLTJCSF RvR0pzcUNp QTFjM1czUW RDWVNRYUlr OEE4eGpsNm VwV29IakRm TzdxMi0yQm xqbWNILTJC MHZod3AzTG JsbXdNbGct M0QtM0RqTG s2XzRtZ0tM UkVHUXIxeG 1YMHBnQ1FR blUyaXdxWm 1ZT2lYdDd1 SkZKcHVDNT Q0Zy0yQnJX LTJGczVmMD dXbkFwWUVt ckctMkI0b2 1OVWtVOFJp RkJ1ei0yQn B0cjhTZ1Ey YmlRdzZjNn hzNDA0OHJz RDctMkJ1ZW 5qTmJGbXJj Z1pRa3c1bi 0yQkUwQnVZ bXdJTEVUdk 45VFVCUm9S dlFBbUhlZn ZGQXFsVEVu OGpTcUpGcW 03cHI1QTlp ZzBmaE9CcU 93SUpoR3hD V3RYd0ZkVW hxc3BMb0sw QWNTaGVlYj FCTDBEVEtu anJQUnNpcn MtMkJMOEY1 SmxheTVQek g3Mll3YWhs dmVyeDl2Tz Z6Nm1Xai0y QlREeEJSM3 NOYWdQU0U2 YVd6dmFTQW 1sMU1kc1Jo M1h4aEtjUn FMTE43c1BB ckxFbS0yQk gtMkJEOXlL UjRYWjg4cX o0SkQwdGNh Qk9UaUxIRD BsZ0hONmhQ cXlRYWFHRV hGQmpsYXU0 YVVyRXdORl BRZGI4QUwt MkJjUTM2dk prZ1p1TGdC Q0F0QXd2NH JsOVJDdkpi RjRJTGwxNX NJcFNQVlJY N2xydmtWY1 BjdkxJS1F2 djJPblRPZ2 hnTVZEbllr TmVhUmlRTk Q3ZXpxdzNu UTJaNHZCeW hjZVFQcGx4 MVhTTHFNNz VHRWFncVQ2 ck5kc05ubG diVUZJbFZQ bFFneWYyZW lNdk42WHlI WWw1bzRxWF RnUHdpelpQ YzI4bjE3ck FkWHZiVDFj NnRKR0N0Zn RjcE42b2ot MkZsZExDTV FhYU1jYi0y QmFxR0lxZl VLc3p3RG9N cnBtN0dlcm xmcTJPbWtk UEJ3MjFFbz BSSDAyMnBV ZURybEY1M0 NOWEt1S05w WGNmLTJGSk tpeFB2ZTcw MGhwWmFqbk NUUWswNzNO T3RCYXF2Mz BhMm1nMmF5 SkxReHJoVV dXUjNPNFZJ cGNkT3Jacl RIVmlmM1JX bEFRaDZmMk NRQ0VDc2J1 OGItMkJGN0 ZYNG9jUW9V TWEzbW12Zj VYd1lhSFlN MzFoTTNWNF ZORmRhMg== &i=NThlN2N jYzYyOTljZ jkxNGY4YmM 0ZGE3&t=OC t3THdBT25H S2pyeUdoSk 9NY25hRU02 SlFET3BwSl BrOE9kUEdQ VHJDRT0=&h =b4724174b 03f4ea39ad cca6ec84dc 529&s=AVNP UEhUT0NFTk NSWVBUSVan joOam2PSWZ ZXYcKt7aVl TK6quiW7kY 6waH-p5Ism 96qrAu1mvX L4EDhOrRyQ F9jrk6MY03 SMFoQ6gMGe ti7dWBks3Q 0GDvEDbSaP c7xwzg MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 6184 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2164 --fi eld-trial- handle=195 6,i,543305 4103107749 602,658311 0671494093 231,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 6776 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= audio.mojo m.AudioSer vice --lan g=en-US -- service-sa ndbox-type =audio --m ojo-platfo rm-channel -handle=48 08 --field -trial-han dle=1956,i ,543305410 3107749602 ,658311067 1494093231 ,262144 -- disable-fe atures=Opt imizationG uideModelD ownloading ,Optimizat ionHints,O ptimizatio nHintsFetc hing,Optim izationTar getPredict ion /prefe tch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 6740 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= video_capt ure.mojom. VideoCaptu reService --lang=en- US --servi ce-sandbox -type=none --mojo-pl atform-cha nnel-handl e=5884 --f ield-trial -handle=19 56,i,54330 5410310774 9602,65831 1067149409 3231,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
⊘No configs have been found
⊘No yara matches
⊘No Sigma rule has matched
⊘No Snort rule has matched
Click to jump to signature section
Show All Signature Results
Phishing |
---|
Source: | DOM page: | ||
Source: | DOM page: |
Source: | ML Model on OCR Text: |
Source: | HTTP Parser: |