Edit tour
Windows
Analysis Report
sample-617931-aedd647ef0001c606b42212abf5b8092.zip
Overview
General Information
Detection
Captcha Phish HTMLPhisher
Score: | 76 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Phishing site detected (based on favicon image match)
Yara detected HtmlPhish10
Yara detected Captcha Phish
Phishing site detected (based on image similarity)
Invalid 'forgot password' link found
HTML body contains low number of good links
Invalid T&C link found
No HTML title found
Classification
- System is start
- chrome.exe (PID: 4860 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --enab le-automat ion --sin gle-argume nt C:\User s\eyup\App Data\Local \Temp\Temp 1_sample-6 17931-aedd 647ef0001c 606b42212a bf5b8092.z ip\ATT0005 3210.htm MD5: 2A7452F3E3165FECBFCCAD71B04E5C37) - chrome.exe (PID: 5524 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -field-tri al-handle= 1764,18327 7695597454 15343,2734 5931097671 90632,1310 72 --lang= en-US --se rvice-sand box-type=n one --mojo -platform- channel-ha ndle=2104 /prefetch: 8 MD5: 2A7452F3E3165FECBFCCAD71B04E5C37)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CaptchaPhish_1 | Yara detected Captcha Phish | Joe Security | ||
JoeSecurity_CaptchaPhish | Yara detected Captcha Phish | Joe Security | ||
JoeSecurity_HtmlPhish_10 | Yara detected HtmlPhish_10 | Joe Security |
⊘No Sigma rule has matched
⊘No Snort rule has matched
Click to jump to signature section
Show All Signature Results
Phishing |
---|
Source: |