Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15711CB28644D4B2F638391B227B33F2D3290D501CAA72B4046F883FC0BC5D59C86B0C5 |
|
CONTENT
ssdeep
|
12:nwfRNbuBIhVZKSoWfjlBlWouGbs4S+dc+s5HHqvRlQeloJbIWg0CKKT:neNb3hV9F2SN0nqZqe23CKw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc6633998e668c9b |
|
VISUAL
aHash
|
3c00181818181800 |
|
VISUAL
dHash
|
7000303030101000 |
|
VISUAL
wHash
|
7e3818183c3c0000 |
|
VISUAL
colorHash
|
380000001c0 |
|
VISUAL
cropResistant
|
7000303030101000 |
⢠Threat: Potential data harvesting due to form submission
⢠Target: MEXC users
⢠Method: Website asks users to log in
⢠Exfil: Data sent to unknown API, custom data exfiltration
⢠Indicators: Recent domain registration, javascript form submission
⢠Risk: LOW - Potentially legitimate, but requires careful handling of personal information due to form submission.
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.