Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B5618561804DA86FC2534881F627BA15A147441E8B538E963FA5C696FDCAD32DE313CE |
|
CONTENT
ssdeep
|
96:cSVkC3VSuNSadcadaamUadavadasBsDBSZBijB7ne:jVkCtIwcwhmUwmw7+Re |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
eb79c4846b7a3826 |
|
VISUAL
aHash
|
c2ff818181ffffff |
|
VISUAL
dHash
|
16d61b3b63134d0d |
|
VISUAL
wHash
|
c0da818101ffe7e7 |
|
VISUAL
colorHash
|
07000400049 |
|
VISUAL
cropResistant
|
16d61b3b63134d0d,2d2d929292d27065,66aaca4a2a2aaa66,0f3371696971310f,0f71616969696969,0f3371696971310f,33f5c4653594b567,6969713313061d3a,0000101010100800 |
• Threat: Phishing
• Target: YONO SBI customers
• Method: Impersonation and Social Engineering
• Exfil: Likely account credentials and potentially financial information.
• Indicators: Unrelated domain, urgency, and reward offers.
• Risk: HIGH
The phishing site attempts to steal the user's login credentials by providing a fake login form that mimics the appearance of the YONO SBI login portal. Once the user enters their username and password, the attackers gain access to the account.
The attackers leverage social engineering techniques like the promise of rewards and the need to complete KYC to create a sense of urgency and convince users to submit their credentials.
Pages with identical visual appearance (based on perceptual hash)