Edit tour
Windows
Analysis Report
_#U266c_Play Mp3MSG(#U00f0#U0178#U201c#U017e)899 ___3pm .htm
Overview
General Information
Detection
HTMLPhisher
Score: | 60 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Yara detected HtmlPhish27
Phishing site detected (based on favicon image match)
HTML document with suspicious name
IP address seen in connection with other malware
Classification
- System is w10x64
- chrome.exe (PID: 3532 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" --sta rt-maximiz ed --enabl e-automati on "C:\Use rs\user\De sktop\_#U2 66c_Play M p3MSG(#U00 f0#U0178#U 201c#U017e )899 ___3p m .htm MD5: C139654B5C1438A95B321BB01AD63EF6) - chrome.exe (PID: 6700 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -field-tri al-handle= 1588,42067 7101781303 0206,17947 6627183624 80258,1310 72 --lang= en-US --se rvice-sand box-type=n etwork --e nable-audi o-service- sandbox -- mojo-platf orm-channe l-handle=1 648 /prefe tch:8 MD5: C139654B5C1438A95B321BB01AD63EF6)
- cleanup
⊘No configs have been found
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_HtmlPhish_27 | Yara detected HtmlPhish_27 | Joe Security |
⊘No Sigma rule has matched
⊘No Snort rule has matched
Click to jump to signature section
Show All Signature Results
Phishing |
---|
Source: | File source: |
Source: | Matcher: |
Source: | Directory created: | Jump to behavior | ||
Source: | Directory created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | IP Address: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |