Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18CF2953671105127039382D6BB26374EE2A58248CB37069DBAFCA78C5BD3DA4DF33665 |
|
CONTENT
ssdeep
|
384:HCCZmcUA2lW12NN1VK7n35Db6WVMzZoqwJ6vlEFG:HCCTvEe80Mzeqw2lKG |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9757ea1819c54f61 |
|
VISUAL
aHash
|
00000000003fffff |
|
VISUAL
dHash
|
686c4cdcfc7c002b |
|
VISUAL
wHash
|
0006240e04ffffff |
|
VISUAL
colorHash
|
07000000c00 |
|
VISUAL
cropResistant
|
50d4292040819140,8000618181410080,5454a6a6a2823460,00204181a1014180,8a922402c8d22022,6c002957562b232b,586c4ccc6cdcbc7c |
โข Threat: Phishing
โข Target: Unknown
โข Method: Forms, Javascript Obfuscation
โข Exfil: https://xyberito-acoes-ai.org/assets/submit.php
โข Indicators: Suspicious domain, obfuscation, form actions to external URL
โข Risk: Alto
The site uses a form to collect user data, which is then likely sent to a remote server. The obfuscated Javascript is likely used to bypass security measures and/or hide its malicious intent.
Javascript can be used to inject malicious code (e.g., keyloggers, redirects) into a user's browser, enabling data theft and/or the compromise of the user's system.
Pages with identical visual appearance (based on perceptual hash)