Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B9225311115537B726C383B27A31EBED73CA1A99C91B8B0123F8870B6FAEDC1CE15659 |
|
CONTENT
ssdeep
|
96:nI34brR4Bgi0nQDRvlmpQ6Xb13IfzGDM7357eOIuKyzA/K7if9TKWDugviuz+66v:FbteA55sgg0DCu4m1IK6m0P |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b84739c6643cc739 |
|
VISUAL
aHash
|
00000000ffffcfcf |
|
VISUAL
dHash
|
9631e2868e101e1e |
|
VISUAL
wHash
|
00000072ffffcfcf |
|
VISUAL
colorHash
|
03000000180 |
|
VISUAL
cropResistant
|
e6e68ea6101e1e9e,80b280935bc08080,960c30f2daa6c68e,1919981811111313 |
โข Threat: None detected
โข Target: Not applicable
โข Method: Not applicable
โข Exfil: Not applicable
โข Indicators: None
โข Risk: LOW - Legitimate Discord content
The phishing kit captures Discord login credentials by presenting a cloned login interface. Submitted credentials are likely exfiltrated to an attacker-controlled server for account takeover.
The kit includes functionality to intercept one-time passwords (OTPs) or 2FA codes, enabling attackers to bypass multi-factor authentication and gain full access to victim accounts.
Malicious JavaScript file containing OTP stealer and personal information harvesting code.
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. TARGET RECEIVES PHISHING LINK โ
โ - Fake Discord message with malicious URL โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. VICTIM LANDS ON FAKE DISCORD PAGE โ
โ - Clone of legitimate Banking login portal โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. CREDENTIAL INPUT โ
โ - User enters Banking credentials โ
โ - Form appears identical to Discord login โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. DATA EXFILTRATION โ
โ - Credentials sent via HTTP POST โ
โ - Standard form submission to attacker server โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. TARGET RECEIVES PHISHING LINK โ
โ - Fake Discord message with malicious URL โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. VICTIM LANDS ON FAKE DISCORD PAGE โ
โ - Clone of legitimate Banking login portal โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. CREDENTIAL INPUT โ
โ - User enters Banking credentials โ
โ - Form appears identical to Discord login โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. DATA EXFILTRATION โ
โ - Credentials sent via HTTP POST โ
โ - Standard form submission to attacker server โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Pages with identical visual appearance (based on perceptual hash)