Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BB1299A911A38EAF014384E471AAEF5F71D5C208CFA7D24D71AC51A9B7DBC53ACD026C |
|
CONTENT
ssdeep
|
192:+kDfM6x5dL0D8HmVdkDdHkQ7VzD8H5jkebij87DdHQj7vHj1Njzy:jDjdL0D8HwaDdHJBD8H5jkebij87DdH/ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a6d8d87266d95272 |
|
VISUAL
aHash
|
7c5f676767673f7f |
|
VISUAL
dHash
|
99bc8ccdcfcdf0c6 |
|
VISUAL
wHash
|
6c1f072723071f37 |
|
VISUAL
colorHash
|
07001008088 |
|
VISUAL
cropResistant
|
99bc8ccdcfcdf0c6,4098606424208800,010061c9c9010101 |
โข Threat: Potential credential harvesting
โข Target: DocuSign users
โข Method: Prompting users to sign in with email providers to view a secure cloud document.
โข Exfil: Unknown
โข Indicators: Third-party sign-in options, request to choose email provider.
โข Risk: LOW - Requires user interaction to potentially expose credentials.
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 24 techniques to evade detection by security scanners and make reverse engineering more difficult.
| ID | Portuguese | English | Trigger |
|---|---|---|---|
```
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ VICTIM VISITS PHISHING PAGE โ
โ (Fake login, verification, support page) โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ VICTIM ENTERS CREDENTIALS (Form 5) โ
โ โ
โ - Email/Username โ
โ - Password โ
โ - 2FA code (if requested) โ
โ - Seed phrase (if crypto-related) โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ FORM SUBMISSION (JavaScript POST) โ
โ โ
โ Credentials sent to: โ
โ โ Telegram bot (real-time notification) โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ ๐ TELEGRAM NOTIFICATION (Attacker alerted) โ
โ โ
โ Message contains: โ
โ - Victim's email/username โ
โ - Password โ
โ - IP address โ
โ - User agent โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ VICTIM SEES FAKE ERROR / REDIRECT โ
โ โ
โ - "Incorrect password, try again" โ
โ - "Account locked, contact support" โ
โ - Redirect to legitimate site โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ ๐จ CREDENTIALS STOLEN โ
โ โ
โ Attacker can now: โ
โ - Access victim's account โ
โ - Bypass 2FA (if captured) โ
โ - Steal funds (if crypto seed phrase) โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
```
```
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ VICTIM VISITS PHISHING PAGE โ
โ (Fake login, verification, support page) โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ VICTIM ENTERS CREDENTIALS (Form 5) โ
โ โ
โ - Email/Username โ
โ - Password โ
โ - 2FA code (if requested) โ
โ - Seed phrase (if crypto-related) โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ FORM SUBMISSION (JavaScript POST) โ
โ โ
โ Credentials sent to: โ
โ โ Telegram bot (real-time notification) โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ ๐ TELEGRAM NOTIFICATION (Attacker alerted) โ
โ โ
โ Message contains: โ
โ - Victim's email/username โ
โ - Password โ
โ - IP address โ
โ - User agent โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ VICTIM SEES FAKE ERROR / REDIRECT โ
โ โ
โ - "Incorrect password, try again" โ
โ - "Account locked, contact support" โ
โ - Redirect to legitimate site โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ ๐จ CREDENTIALS STOLEN โ
โ โ
โ Attacker can now: โ
โ - Access victim's account โ
โ - Bypass 2FA (if captured) โ
โ - Steal funds (if crypto seed phrase) โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
```
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain