Edit tour
Windows
Analysis Report
https://google.com/amp/%F0%9F%84%B8%F0%9F%84%BF%F0%9F%84%B5%F0%9F%85%82.%E2%93%98%E2%93%9E/ipfs/bafybeidf2ghv5vakeqlcqqvzfsett7uzseqmmutnuaestozqiouef2rq2y#XFrank.Albano@lcatterton.com
Overview
General Information
Detection
HTMLPhisher
Score: | 60 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Yara detected HtmlPhish75
Found HTTP page in a blob
Uses IPFS gateway to access IPFS content in browser (often used in phishing/scams)
Uses the Telegram API (likely for C&C communication)
Detected suspicious crossdomain redirect
HTML body with high number of embedded images detected
Stores files to the Windows start menu directory
URL contains potential PII (phishing indication)
Classification
- System is w10x64_ra
- chrome.exe (PID: 5316 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 6972 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2132 --fi eld-trial- handle=183 6,i,102424 8719257754 4880,15801 6022981555 33034,2621 44 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction / prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 6616 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://googl e.com/amp/ %F0%9F%84% B8%F0%9F%8 4%BF%F0%9F %84%B5%F0% 9F%85%82.% E2%93%98%E 2%93%9E/ip fs/bafybei df2ghv5vak eqlcqqvzfs ett7uzseqm mutnuaesto zqiouef2rq 2y#XFrank. Albano@lca tterton.co m" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
⊘No configs have been found
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_HtmlPhish_75 | Yara detected HtmlPhish_75 | Joe Security |
⊘No Sigma rule has matched
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
Phishing |
---|
Source: | File source: |
Source: | DOM page: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | Sample URL: |
Source: | HTTP Parser: |
Source: | Binary string: |