Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A47273B28318B6BE64DBCAE4AE2A733A5156D04BF9E6114151FD8778C7C3CC0EE27540 |
|
CONTENT
ssdeep
|
192:wWdYuDkdT49zG7zToJ0sq3/bTpxIIIImucpqpxIIIImiEZp/VtdwoIq5K65Jn:wWYuDk1MJZN9ndwoIqw2Jn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
990ce6f3cc88e6e2 |
|
VISUAL
aHash
|
00000000ffffffff |
|
VISUAL
dHash
|
d7b3d7b3b25c5a0c |
|
VISUAL
wHash
|
00000000ffffffff |
|
VISUAL
colorHash
|
06000000038 |
|
VISUAL
cropResistant
|
000405151505048a,b2325a5a5a5a120c,f7f3b3f3f3d7b3b2 |
โข Threat: Phishing
โข Target: NuBank (Nubank)
โข Method: Impersonation using a look-alike website.
โข Exfil: Unknown, likely to steal credentials and financial data
โข Indicators: Recent domain, domain mismatch, visual similarity, obfuscated javascript.
โข Risk: High
The phishing site is designed to steal user credentials (username and password) by tricking users into entering them on a fake login page that closely resembles the genuine NuBank website.
Once a user logs in, they can be redirected to a page that downloads malware.
fbevents.jsPages with identical visual appearance (based on perceptual hash)