Windows
Analysis Report
https://www.google.com/url?hl=en&q=https://LUXJOPTE.rheyynfscnzpvliir.com/mPTeCo?EMCitPBrZZ%3DrqDowxGuLLU%26NXhzvrRYgNtSD%3DoQsSXcEum%26UPWeNpQpmkEF%3DgzDovXdEX%26YTuNBaznPYeh%3Dhttps%3A%2F%2FIECifASBSc.com%26bUwyXNNjHVqZq%3DTLTixShk%26bktSIvBiToIBj%3DSEcBExsX%26cDolpuBDmRW%3DhzJbwPJjN%26hlhsV
Overview
General Information
Detection
Score: | 1 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Detected suspicious crossdomain redirect
HTML body contains password input but no form action
Classification
- System is w10x64
chrome.exe (PID: 5444 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 5596 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=2500,i ,798092824 9596826801 ,128862549 4181489211 0,262144 - -disable-f eatures=Op timization GuideModel Downloadin g,Optimiza tionHints, Optimizati onHintsFet ching,Opti mizationTa rgetPredic tion --var iations-se ed-version =20250306- 183004.429 000 --mojo -platform- channel-ha ndle=2584 /prefetch: 3 MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 4404 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= audio.mojo m.AudioSer vice --lan g=en-US -- service-sa ndbox-type =audio --n o-pre-read -main-dll --field-tr ial-handle =2500,i,79 8092824959 6826801,12 8862549418 14892110,2 62144 --di sable-feat ures=Optim izationGui deModelDow nloading,O ptimizatio nHints,Opt imizationH intsFetchi ng,Optimiz ationTarge tPredictio n --variat ions-seed- version=20 250306-183 004.429000 --mojo-pl atform-cha nnel-handl e=6040 /pr efetch:8 MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 7468 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= video_capt ure.mojom. VideoCaptu reService --lang=en- US --servi ce-sandbox -type=none --no-pre- read-main- dll --fiel d-trial-ha ndle=2500, i,79809282 4959682680 1,12886254 9418148921 10,262144 --disable- features=O ptimizatio nGuideMode lDownloadi ng,Optimiz ationHints ,Optimizat ionHintsFe tching,Opt imizationT argetPredi ction --va riations-s eed-versio n=20250306 -183004.42 9000 --moj o-platform -channel-h andle=6060 /prefetch :8 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 7104 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://www.g oogle.com/ url?hl=en& q=https:// LUXJOPTE.r heyynfscnz pvliir.com /mPTeCo?EM CitPBrZZ%3 DrqDowxGuL LU%26NXhzv rRYgNtSD%3 DoQsSXcEum %26UPWeNpQ pmkEF%3Dgz DovXdEX%26 YTuNBaznPY eh%3Dhttps %253A%252F %252FIECif ASBSc.com% 26bUwyXNNj HVqZq%3DTL TixShk%26b ktSIvBiToI Bj%3DSEcBE xsX%26cDol puBDmRW%3D hzJbwPJjN% 26hlhsVPSl YGIJ%3Dwys qjWOSX" MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
⊘No configs have been found
⊘No yara matches
⊘No Sigma rule has matched
⊘No Suricata rule has matched
- • Phishing
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
Show All Signature Results
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Binary string: |