Click to jump to signature section
Source: 4.9.pages.csv | Malware Configuration Extractor: Evil Proxy {"pagemsg": "{\\\"LoginPage\\\":{\\\"text\\\":null,\\\"color\\\":\\\"black\\\"},\\\"PassPage\\\":{\\\"text\\\":null,\\\"color\\\":\\\"black\\\"}}", "semail": "", "urlx": "script.php", "lmode": "b"} |
Source: https://hrv56k8ryi.ferrovelho.shop/m/86efbfca1e206ccf7a31f8b3bf14aa5e.htm | LLM: Score: 9 Reasons: The brand 'Microsoft' is a well-known global technology company., The legitimate domain for Microsoft is 'microsoft.com'., The provided URL 'hrv56k8ryi.ferrovelho.shop' does not match the legitimate domain for Microsoft., The domain 'ferrovelho.shop' is unusual and not associated with Microsoft., The subdomain 'hrv56k8ryi' appears random and does not provide any legitimate context., The use of a '.shop' domain extension is unusual for a technology company like Microsoft., The presence of input fields for 'Email or phone' is common in phishing attempts targeting Microsoft accounts. DOM: 4.10.pages.csv |
Source: Yara match | File source: 4.10.pages.csv, type: HTML |
Source: Yara match | File source: 4.9.pages.csv, type: HTML |
Source: Yara match | File source: 5.11.pages.csv, type: HTML |
Source: Yara match | File source: 4.10.pages.csv, type: HTML |
Source: Yara match | File source: 4.9.pages.csv, type: HTML |
Source: Yara match | File source: 5.11.pages.csv, type: HTML |
Source: https://hrv56k8ryi.ferrovelho.shop/m/86efbfca1e206ccf7a31f8b3bf14aa5e.htm | Matcher: Template: microsoft matched with high similarity |
Source: https://hrv56k8ryi.ferrovelho.shop/m/86efbfca1e206ccf7a31f8b3bf14aa5e.htm# | Matcher: Template: microsoft matched with high similarity |
Source: https://hrv56k8ryi.ferrovelho.shop/m/86efbfca1e206ccf7a31f8b3bf14aa5e.htm | Matcher: Found strong image similarity, brand: MICROSOFT |
Source: https://hrv56k8ryi.ferrovelho.shop/m/86efbfca1e206ccf7a31f8b3bf14aa5e.htm | Matcher: Template: microsoft matched |
Source: https://hrv56k8ryi.ferrovelho.shop/m/86efbfca1e206ccf7a31f8b3bf14aa5e.htm | Matcher: Template: microsoft matched |
Source: https://hrv56k8ryi.ferrovelho.shop/m/86efbfca1e206ccf7a31f8b3bf14aa5e.htm# | Matcher: Template: microsoft matched |
Source: https://hrv56k8ryi.ferrovelho.shop/m/86efbfca1e206ccf7a31f8b3bf14aa5e.htm | HTTP Parser: Number of links: 0 |
Source: https://premierbb.sharefile.com/share/view/189361297164461c | HTTP Parser: Base64 decoded: {"version":3,"sources":["webpack://./node_modules/react-loading-skeleton/dist/skeleton.css"],"names":[],"mappings":"AAAA;EACE;IACE,2BAA2B;EAC7B;AACF;;AAEA;EACE,qBAAqB;EACrB,0BAA0B;EAC1B,0BAA0B;EAC1B,6BAA6B;EAC7B,+BAA+B,EAAE,qBAAqB;;EAEtD,mCAAmC;;EAEnC,WAA... |
Source: https://hrv56k8ryi.ferrovelho.shop/m/86efbfca1e206ccf7a31f8b3bf14aa5e.htm | HTTP Parser: Title: KZQ8EW470EOCVG9O4PV3 does not match URL |
Source: https://hrv56k8ryi.ferrovelho.shop/m/86efbfca1e206ccf7a31f8b3bf14aa5e.htm | HTTP Parser: Invalid link: Terms of use |
Source: https://hrv56k8ryi.ferrovelho.shop/m/86efbfca1e206ccf7a31f8b3bf14aa5e.htm | HTTP Parser: Invalid link: Privacy & cookies |
Source: https://hrv56k8ryi.ferrovelho.shop/m/86efbfca1e206ccf7a31f8b3bf14aa5e.htm | HTTP Parser: Invalid link: Terms of use |
Source: https://hrv56k8ryi.ferrovelho.shop/m/86efbfca1e206ccf7a31f8b3bf14aa5e.htm | HTTP Parser: Invalid link: Privacy & cookies |
Source: file:///C:/Users/user/Downloads/Action-Confidential.pdf | HTTP Parser: No favicon |
Source: file:///C:/Users/user/Downloads/Action-Confidential.pdf | HTTP Parser: No favicon |
Source: https://hrv56k8ryi.ferrovelho.shop/m/86efbfca1e206ccf7a31f8b3bf14aa5e.htm | HTTP Parser: No <meta name="author".. found |
Source: https://hrv56k8ryi.ferrovelho.shop/m/86efbfca1e206ccf7a31f8b3bf14aa5e.htm | HTTP Parser: No <meta name="author".. found |
Source: https://hrv56k8ryi.ferrovelho.shop/m/86efbfca1e206ccf7a31f8b3bf14aa5e.htm | HTTP Parser: No <meta name="copyright".. found |
Source: https://hrv56k8ryi.ferrovelho.shop/m/86efbfca1e206ccf7a31f8b3bf14aa5e.htm | HTTP Parser: No <meta name="copyright".. found |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:49709 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:49717 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 2.19.74.158:443 -> 192.168.2.6:49726 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 2.19.74.158:443 -> 192.168.2.6:49728 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.6:49751 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.202.163.200:443 -> 192.168.2.6:49787 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:49903 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.6:49998 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.6:50125 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.202.163.200:443 -> 192.168.2.6:50177 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:50193 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:50259 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:50314 version: TLS 1.2 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.19.74.158 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.19.74.158 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.19.74.158 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.19.74.158 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.19.74.158 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.19.74.158 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.19.74.158 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.19.74.158 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.19.74.158 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.19.74.158 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.19.74.158 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.19.74.158 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.19.74.158 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.19.74.158 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.19.74.158 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.19.74.158 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.19.74.158 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.19.74.158 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.19.74.158 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.107.246.45 |
Source: global traffic | HTTP traffic detected: HTTP/1.1 200 OKContent-Type: text/cssContent-Length: 2944Connection: keep-aliveDate: Wed, 18 Sep 2024 22:47:57 GMTLast-Modified: Wed, 18 Sep 2024 21:13:25 GMTETag: "54bf75d03e588470d1a76cdbd7ab5c1d"x-amz-server-side-encryption: AES256Cache-Control: max-age=31536000Content-Encoding: gzipx-amz-version-id: utZr4xtDVNV4ci6RrOc0u53V1VtRvrrGAccept-Ranges: bytesServer: AmazonS3X-Cache: Hit from cloudfrontVia: 1.1 41f60102fc29156bc5001d6646f75c02.cloudfront.net (CloudFront)X-Amz-Cf-Pop: FRA2-C1X-Amz-Cf-Id: zRx-3O5fcZ19CxYH5QpcDcD7xGmcjjbEIpZ4C14RM95fg8Tv1_LO4g==Age: 1797538Referrer-Policy: no-referrerX-Content-Type-Options: nosniffData Raw: 1f 8b 08 08 6f 42 eb 66 00 03 6d 61 69 6e 2e 63 73 73 00 c5 5b e9 92 a3 38 12 fe bf 4f c1 76 c7 46 57 75 80 c7 1c be 70 cc c4 ee ff 7d 82 9d e8 e8 10 48 36 da 92 81 06 b9 ca d5 84 e7 d9 57 12 87 25 24 83 5c 7b f5 44 4c 1b 91 99 ca f3 4b 01 d9 10 bf 2e 48 e9 95 c5 c9 ab 8a 82 3a fd c5 a1 a8 d8 ff 30 22 70 41 d0 11 a4 ef 4d 59 d4 98 e2 22 8f 41 52 17 e4 4c d1 9e a0 03 8d 97 7b 5a 94 ec ff 27 50 1d 71 ee 25 05 a5 c5 29 f6 83 f2 72 85 b6 b2 1d 02 12 44 66 76 78 40 5c 8d 08 4a e9 9c c6 25 80 10 e7 c7 41 77 f6 23 29 2a 88 aa d8 2f 2f 0e e3 c0 d0 f9 bc 5e af 1f de d8 29 4a be 6d 33 6c b0 08 d0 e9 01 29 14 5d 28 a8 10 70 ed 59 70 5e 9e e9 ef f4 bd 44 bf 72 ee 6f ff 07 db c7 2a c4 b1 77 2a 7e 32 c2 f4 5c 7b 38 cf 51 75 73 48 bf 59 5e e4 e8 61 f7 fe 17 04 2f da 88 d5 7f c7 f5 6c da 54 f8 98 51 a3 0b 1f df f0 b6 57 85 08 a0 f8 15 8d ea 68 fd 50 19 75 52 db 50 e8 76 7c 40 d2 a8 30 07 2d 21 ae 4b 02 de e3 84 14 e9 cb a4 dc 56 99 45 7d 4e 4e 78 ce b7 57 99 71 91 81 da 03 17 5c 3b 5f 9b a4 b8 78 35 fe c9 dd dd 06 98 f9 e7 72 87 9a 5f dd f6 a9 29 53 38 75 fe 8c 4f 65 51 51 90 d3 3b 5c 0b 61 7e dd f4 86 1d 08 ba ec ff 79 ae 29 3e bc 7b 69 91 53 94 53 b1 e8 31 89 d5 3d 29 c2 56 d7 7c af 4d de 3b 37 fb 92 6f 2d cd 00 2c de 44 0e ef 8b 33 25 38 47 6d 42 4f 6c da 16 de 17 2e e7 cb b7 3b 9b c8 84 e8 04 30 b1 a2 a4 e8 3e 9d 9d 4d 6f 18 d2 2c f6 97 cb bf dc b1 a0 c7 6b 05 2f 27 34 b3 46 80 a9 ed fe 4d 21 7d 05 03 82 8f b9 87 29 3a d5 71 ca 92 04 55 7a 09 f7 58 e1 89 64 0f 96 d2 4a 8b 26 db f2 5e 36 ab 25 dd 49 1e 98 fa ad 84 5c 8f 0b be 66 f4 44 9a b4 20 45 15 7f 5e 2e 99 25 20 7d 39 56 c5 39 87 71 75 4c c0 d3 d2 15 ff 3d 5f 93 02 be f3 0e e3 42 e2 42 ea 42 e8 9e 89 5b 10 97 60 37 f3 Data Ascii: oBfmain.css[8OvFWup}H6W%$\{DLK.H:0"pAMY"ARL{Z'Pq%)rDfvx@\J%Aw#)*//^)Jm3l)](pYp^Dro*w*~2\{8QusHY^a/lTQWhPuRPv|@0-!KVE}NNxWq\;_x5r |