Play interactive tourEdit tour
Windows Analysis Report payment.html
Overview
General Information
Detection
HTMLPhisher
Score: | 88 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Multi AV Scanner detection for submitted file
Yara detected HtmlPhish6
Yara detected HtmlPhish44
Yara detected obfuscated html page
HTML document with suspicious title
Phishing site detected (based on various OCR indicators)
HTML document with suspicious name
Phishing site detected (based on logo template match)
None HTTPS page querying sensitive user data (password, username or email)
No HTML title found
HTML body contains low number of good links
Suspicious form URL found
IP address seen in connection with other malware
Classification
Process Tree |
---|
|
Malware Configuration |
---|
No configs have been found |
---|
Yara Overview |
---|
Initial Sample |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Obshtml | Yara detected obfuscated html page | Joe Security | ||
JoeSecurity_HtmlPhish_44 | Yara detected HtmlPhish_44 | Joe Security | ||
JoeSecurity_HtmlPhish_6 | Yara detected HtmlPhish_6 | Joe Security |
Sigma Overview |
---|
No Sigma rule has matched |
---|
Jbx Signature Overview |
---|
Click to jump to signature section
Show All Signature Results
AV Detection: |
---|
Multi AV Scanner detection for submitted file | Show sources |
Source: | Virustotal: | Perma Link | ||
Source: | Metadefender: | Perma Link | ||
Source: | ReversingLabs: |
Phishing: |
---|
Yara detected HtmlPhish6 | Show sources |
Source: | File source: | ||
Source: | File source: |
Yara detected HtmlPhish44 | Show sources |
Source: | File source: |
Yara detected obfuscated html page | Show sources |
Source: | File source: |
Phishing site detected (based on various OCR indicators) | Show sources |
Source: | OCR Text: | ||
Source: | OCR Text: |