Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B8E229B4A230D335B1C247E8DA6425687A5FE1DCD7C695B4F388AF11B0D6CE8D5260CB |
|
CONTENT
ssdeep
|
384:4rAneu0TPRhiXkdvNTDhPhLxeAxeDWNW1Tp34PxeeJEmuW3AskoRWeMd:4rAneuahhPhleMeDGCSPxeeWmHBW |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d1633ebc681f1c68 |
|
VISUAL
aHash
|
806660f0f8de8e00 |
|
VISUAL
dHash
|
5cdcdad391346c31 |
|
VISUAL
wHash
|
806626f0f8debf90 |
|
VISUAL
colorHash
|
38018000600 |
|
VISUAL
cropResistant
|
d0f066a63936e0f2,f8b2b4c192c6c5ce,00100c4c4c0c1008,5cdcdad391346c31 |
โข Threat: Credential Harvesting
โข Target: Unsuspecting users
โข Method: Deception through fake registration form.
โข Exfil: wss://gambler-work.com/api/ws (WebSocket URL)
โข Indicators: Registration form, celebrity image, free reward claim, obfuscated javascript.
โข Risk: HIGH
The site utilizes a registration form to collect user email addresses and passwords, with the likely intent of stealing those credentials and gaining access to user accounts.
The site uses visual elements (celebrity endorsement) and incentives like 'free reward' to encourage users to enter their credentials. This aims to bypass user's security awareness
fbevents.jsPages with identical visual appearance (based on perceptual hash)