Windows
Analysis Report
http://url7554.impulseup.com/ls/click?upn=u001.9-2FTADgI74e2OWE2P3fvtm3ks0lxIlIFyP5IwbLoDgBuxxxaTOIUzJMW49-2B9jqW6yELBC1ZQRMe6TWLgjPYTu0LiDQ0w3txTcOK6-2FV2ifPZbRaLIwmmOQ1GMQC9dU6RWb2aeLLtDeODHngY3VjjXvJO6oKDlYY-2FrsIGLii2s3kEKAZFDtf-2BL31aMPuCVwlwPCr7PEQRptcwz1QBhdaSd2LGMdK1VJSRTe40dM32Z7Jz2jBBbK0Uw
Overview
General Information
Detection
HTMLPhisher
Score: | 72 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
AI detected phishing page
Yara detected HtmlPhish44
Yara detected obfuscated html page
AI detected suspicious Javascript
Detected use of open redirect vulnerability
Detected suspicious crossdomain redirect
Form action URLs do not match main URL
HTML body contains low number of good links
HTML page contains hidden javascript code
HTML title does not match URL
Suspicious form URL found
Classification
- System is w10x64
chrome.exe (PID: 4316 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 832 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=2248,i ,121168941 0777265454 6,11462018 4702005650 57,262144 --disable- features=O ptimizatio nGuideMode lDownloadi ng,Optimiz ationHints ,Optimizat ionHintsFe tching,Opt imizationT argetPredi ction --va riations-s eed-versio n=20250306 -183004.42 9000 --moj o-platform -channel-h andle=2328 /prefetch :3 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 6772 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://url755 4.impulseu p.com/ls/c lick?upn=u 001.9-2FTA DgI74e2OWE 2P3fvtm3ks 0lxIlIFyP5 IwbLoDgBux xxaTOIUzJM W49-2B9jqW 6yELBC1ZQR Me6TWLgjPY Tu0LiDQ0w3 txTcOK6-2F V2ifPZbRaL IwmmOQ1GMQ C9dU6RWb2a eLLtDeODHn gY3VjjXvJO 6oKDlYY-2F rsIGLii2s3 kEKAZFDtf- 2BL31aMPuC VwlwPCr7PE QRptcwz1QB hdaSd2LGMd K1VJSRTe40 dM32Z7Jz2j BBbK0UwZYo 0lLPRxihoy t5eczvkRV2 tuefWun26R 7i639CvHIP Vt6rH7EVtY 4Yq4-2BX81 bSKNRYMont -2BURzxOXv Irvc-2FmXD xBQFquNv8h Cg-3D-3DOf 7V_1bLtnK9 VzA81xTl66 e5cQEfeWNr WDvGojS6qz pbIWVBQ7lK G2g0aCCOyV obSDuVrLeb ffHMB5eRck n5ACwa2iQe Use2Dj4VAB -2FABJ1Acb 1YvF-2FbDn BdetKvvIMz pE5RxgQY2I AbwQdJhLDS LJUr91tf15 39-2Ft7it4 uBG8JH-2Fo 6agurxFXC9 oi5BHuPPJf C2Yg7NXAY- 2BcEwb3vDW Ugys5pw-3D -3D" MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
⊘No configs have been found
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_HtmlPhish_44 | Yara detected HtmlPhish_44 | Joe Security | ||
JoeSecurity_Obshtml | Yara detected obfuscated html page | Joe Security |
⊘No Sigma rule has matched
⊘No Suricata rule has matched
- • Phishing
- • Compliance
- • Software Vulnerabilities
- • Networking
- • System Summary
Click to jump to signature section
Show All Signature Results
Phishing |
---|
Source: |