Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F8921A29B54E5C62DF33C4C2A4E02D273499E3078A1A09E55BD905B59FD3CF0B989FB4 |
|
CONTENT
ssdeep
|
96:YiryG1T0aP6kDxhHQEDW3wSUPVRUGrkE5K8VzQ/96DeLa1k+fyc2Cm/zSWtILOPo:Yi7Tp2EmrakOUz+yoVX/0/6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dcdd73f1e6260809 |
|
VISUAL
aHash
|
e7fc181818180000 |
|
VISUAL
dHash
|
0f32b3333332440e |
|
VISUAL
wHash
|
ffff3c3c3c3c0000 |
|
VISUAL
colorHash
|
39600008200 |
|
VISUAL
cropResistant
|
06066669c30f0684,0008bc98b9b7bc9d,0f00000000000008,a6a294554d3931c2,0f32b3333332440e |
โข Threat: Potential scam promoting several e-commerce services.
โข Target: Korean-speaking users.
โข Method: Promotion of e-commerce platforms within an unfamiliar service.
โข Exfil: No data exfiltration is apparent.
โข Indicators: Unrelated brands are included in an advertisement. No personal information is requested
โข Risk: LOW - Promotion of multiple services is not necessarily a scam.
The phishing kit captures user credentials through fake login forms. Input fields are intercepted in real-time and transmitted to the attacker's server via HTTP POST requests or WebSocket connections if available.
The kit includes functionality to capture one-time passwords (OTPs) by prompting users to enter OTPs under the guise of account verification or security checks. Captured OTPs are exfiltrated to the attacker.
JavaScript file with potential obfuscated malicious code, though no specific functions or strings were extracted.
Here's a generic ASCII art attack flow diagram for the phishing attack:
```
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. INITIAL CONTACT โ
โ - Victim receives phishing message โ
โ - Message contains link to fake Banking site โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. FAKE SITE VISIT โ
โ - Victim lands on fraudulent login page โ
โ - Page mimics legitimate Banking interface โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. CREDENTIAL ENTRY โ
โ - Victim enters Banking credentials โ
โ - Form appears identical to real bank's โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. DATA CAPTURE โ
โ - Entered credentials collected by attacker โ
โ - Data prepared for exfiltration โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 5. EXFILTRATION โ
โ - Credentials sent via HTTP POST โ
โ - Data transmitted to attacker-controlled server โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
```
Here's a generic ASCII art attack flow diagram for the phishing attack:
```
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. INITIAL CONTACT โ
โ - Victim receives phishing message โ
โ - Message contains link to fake Banking site โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. FAKE SITE VISIT โ
โ - Victim lands on fraudulent login page โ
โ - Page mimics legitimate Banking interface โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. CREDENTIAL ENTRY โ
โ - Victim enters Banking credentials โ
โ - Form appears identical to real bank's โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. DATA CAPTURE โ
โ - Entered credentials collected by attacker โ
โ - Data prepared for exfiltration โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 5. EXFILTRATION โ
โ - Credentials sent via HTTP POST โ
โ - Data transmitted to attacker-controlled server โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
```
Pages with identical visual appearance (based on perceptual hash)