Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T152E3F874E3F5E1F9E106D3E0E5727835369619B9AF01CA4843F98FE8CAA245D895CC83 |
|
CONTENT
ssdeep
|
1536:2Cjo44u44ynOI4DquYW0oxNO96BIn3DmeXYW0ox6O96BIn3DXeoYW0oxDO96BInd:g4DDeoeNeLp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9606e9499bce96c6 |
|
VISUAL
aHash
|
7f0004040400ffff |
|
VISUAL
dHash
|
e08ccceccccca330 |
|
VISUAL
wHash
|
ff0036060600ffff |
|
VISUAL
colorHash
|
02006000000 |
|
VISUAL
cropResistant
|
a2a1859999858180,60e8e8a424666b02,2998dcec4d6c6460,0000000030381e1e,ec8ccceccccccc34 |
⢠Threat: Financial Phishing/Credential Harvesting
⢠Target: Corevest Banking customers
⢠Method: Impersonation of an asset management firm
⢠Exfil: JavaScript-based form submission
⢠Indicators: Obfuscated code, placeholder phone number
⢠Risk: High - credential and PII theft
The site uses a fake banking interface to capture user credentials for 'E-Banking' access, which are then exfiltrated via obfuscated JS requests.
Leverages the aesthetic of a financial institution to build false trust with victims.