Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A4B343214557243B22339F816BC5AB7D518B62D8A337CE07F6F44F2AAFC4E54A94C21E |
|
CONTENT
ssdeep
|
768:H3OHo2sj4P5gqyrm5Yqki96jL0xZoHP49JtA0C6:XOHovj4Po65YJiJxZoHPoC6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fc5c8b0135f848ee |
|
VISUAL
aHash
|
0080d0820200ff81 |
|
VISUAL
dHash
|
1b65243666e00f2b |
|
VISUAL
wHash
|
01b8f082b37eff81 |
|
VISUAL
colorHash
|
02000000006 |
|
VISUAL
cropResistant
|
1849c9342999b136,ae8eaea2b2ae8ea6,9749858189c1c5c7,aa314d4d31452b2b,036b64343626e4aa,2b2b2b3b4c544e4b |
โข Threat: Phishing
โข Target: Bradesco Empresas customers
โข Method: Impersonation and data harvesting
โข Exfil: Unknown (due to obfuscation)
โข Indicators: Domain mismatch, obfuscated code, and forms
โข Risk: High
The site mimics the look and feel of the Bradesco Empresas website to trick users into entering their login credentials. The form data is likely sent to a server controlled by the attackers.
Obfuscated Javascript could be used for advanced keylogging, or redirecting to another phishing site.
Pages with identical visual appearance (based on perceptual hash)