Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T159D21E338040693702A7C2D66671B71FA3D3820ECE234B46A7F4879D2FCAE96DC1665D |
|
CONTENT
ssdeep
|
384:2J/cf6lAtjRKRRDbrXTmhSk8J3GFeyPFPvX:2J/46lAtjRKRRDbbTeSk4GFeyPFPf |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ecad125ed232ee41 |
|
VISUAL
aHash
|
9dfbf3f1f09000ff |
|
VISUAL
dHash
|
293203032323cc24 |
|
VISUAL
wHash
|
00fbf3f1f09000ff |
|
VISUAL
colorHash
|
07000c00000 |
|
VISUAL
cropResistant
|
2932c32303022323,f0e8c9f9b0f8f870,0000000000000000,20c8c12e202b2b21,522323022323c4e4 |
• Threat: Phishing/Credential Harvesting
• Target: Berk Credit Community Bank customers
• Method: Impersonation of a banking portal
• Exfil: Likely via JavaScript form submission
• Indicators: Obfuscated code, suspicious URL
• Risk: High
The site mimics a banking interface to harvest PII and account credentials from unsuspecting users.
Using deceptive forms to capture login details.