Edit tour
Windows
Analysis Report
https://www.msn.com/en-ca/lifestyle/rf-buying-guides/redirect?rf_click_source=list&rf_client_click_id=000000000&rf_dws_location=&rf_item_id=502238318&rf_list_id=3519472&rf_partner_id=353781453390&rf_source=ebay&url=aHR0cHM6Ly9zdXBwb3J0LXRlYW1zbTM2MC5jYy8/aldFUz1iRzl5WlhSMFlTNXJaV0Z1WlVCaGNtTmhaR2xoY
Overview
General Information
Detection
Captcha Phish
Score: | 84 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Phishing site detected (based on shot template match)
Phishing site detected (based on favicon image match)
Yara detected Captcha Phish
Multi AV Scanner detection for domain / URL
Snort IDS alert for network traffic
Phishing site detected (based on image similarity)
Yara signature match
HTML page is missing a favicon
HTML body contains password input but no form action
HTML body contains low number of good links
HTML title does not match URL
Classification
- System is w10x64_ra
- chrome.exe (PID: 6592 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t https:// www.msn.co m/en-ca/li festyle/rf -buying-gu ides/redir ect?rf_cli ck_source= list&rf_cl ient_click _id=000000 000&rf_dws _location= &rf_item_i d=50223831 8&rf_list_ id=3519472 &rf_partne r_id=35378 1453390&rf _source=eb ay&url=aHR 0cHM6Ly9zd XBwb3J0LXR lYW1zbTM2M C5jYy8/ald FUz1iRzl5W lhSMFlTNXJ aV0Z1WlVCa GNtTmhaR2x oYzI5c2RYU nBiMjV6TG1 OdmJRPT0= MD5: 7BC7B4AEDC055BB02BCB52710132E9E1) - chrome.exe (PID: 6872 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2056 --fi eld-trial- handle=174 8,i,106003 7006531704 92,1254414 1793293566 592,131072 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionTarget Prediction /prefetch :8 MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CaptchaPhish_1 | Yara detected Captcha Phish | Joe Security | ||
SUSP_obfuscated_JS_obfuscatorio | Detects JS obfuscation done by the js obfuscator (often malicious) | @imp0rtp3 |
| |
SUSP_obfuscated_JS_obfuscatorio | Detects JS obfuscation done by the js obfuscator (often malicious) | @imp0rtp3 |
|
⊘No Sigma rule has matched
Timestamp: | 192.168.2.31.1.1.163293532027758 05/08/23-16:41:49.940059 |
SID: | 2027758 |
Source Port: | 63293 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | Potentially Bad Traffic |
Timestamp: | 192.168.2.31.1.1.149469532027758 05/08/23-16:43:10.745811 |
SID: | 2027758 |
Source Port: | 49469 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | Potentially Bad Traffic |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Virustotal: | Perma Link |
Phishing |
---|
Source: | Matcher: |
Source: |