Analysis Report https://bit.ly/39kvkUX
Overview
Detection
GRQ Scam
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus detection for URL or domain
Yara detected GRQ Scam
Found iframes
HTML body contains low number of good links
None HTTPS page querying sensitive user data (password, username or email)
Yara detected BitlySuspendedLink
Classification
|
Malware Configuration |
---|
No configs have been found |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_GRQScam | Yara detected GRQ Scam | Joe Security | ||
JoeSecurity_GRQScam | Yara detected GRQ Scam | Joe Security | ||
JoeSecurity_GRQScam | Yara detected GRQ Scam | Joe Security | ||
JoeSecurity_GRQScam | Yara detected GRQ Scam | Joe Security | ||
JoeSecurity_GRQScam | Yara detected GRQ Scam | Joe Security | ||
Click to see the 4 entries |
Sigma Overview |
---|
No Sigma rule has matched |
---|
Signature Overview |
---|
- • AV Detection
- • Phishing
- • Compliance
- • Networking
- • Spam, unwanted Advertisements and Ransom Demands
- • System Summary
Click to jump to signature section
Show All Signature Results
AV Detection: |
---|
Antivirus detection for URL or domain |
Source: | SlashNext: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | File source: | ||
Source: | File source: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Compliance: |
---|
Uses new MSVCR Dlls |
Source: | File opened: | Jump to behavior |
Uses secure TLS version for HTTPS connections |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | HTTP traffic detected: |