Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12E9142215025AE3351E386F4B2DDDB6362EFC228CF80285822FCC7AD0BD5C51B67B955 |
|
CONTENT
ssdeep
|
96:yZ/OyJIVgExhqBQE9tFMhTFk6aMhTtk6Yt:yZ/OxgihqQE9tFMhTFk6aMhTtk6k |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9999996666668b33 |
|
VISUAL
aHash
|
1818181800000000 |
|
VISUAL
dHash
|
b2b2b2b24c200000 |
|
VISUAL
wHash
|
fcfcfcfc00000000 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
a2a2e2a296a89696,b2b2b2b24c200000 |
โข Threat: Phishing
โข Target: Unspecified
โข Method: Credential Harvesting
โข Exfil: /?_task=login
โข Indicators: Unbranded login form, obfuscated Javascript, unrelated domain
โข Risk: High
The attacker attempts to steal user credentials by presenting a fake login form on a suspicious domain. The form submits data to a potentially malicious server.
1. Step 1: User lands on the phishing page (natrajstonex.co.in) disguised as a Roundcube Webmail login portal 2. Step 2: User enters credentials into the login form 3. Step 3: Credentials are captured via JavaScript event handlers and form submission logic 4. Step 4: `http_post()` function sends credentials to the server via AJAX POST requests 5. Step 5: Server-side script processes and exfiltrates the credentials to the attacker's storage or command-and-control (C2) server
1. Step 1: User lands on the phishing page (natrajstonex.co.in) disguised as a Roundcube Webmail login portal 2. Step 2: User enters credentials into the login form 3. Step 3: Credentials are captured via JavaScript event handlers and form submission logic 4. Step 4: `http_post()` function sends credentials to the server via AJAX POST requests 5. Step 5: Server-side script processes and exfiltrates the credentials to the attacker's storage or command-and-control (C2) server
common.js?s=1769006884http_post()submit_messageform()check_compose_input()http_request()set_env()Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain