Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T111412E3165E1016B063B9AC07765AB2FA4D2D708EA538E4953BD47CBDBD1C80DCE21B4 |
|
CONTENT
ssdeep
|
48:D8a9uVWMbaVDwZg21orQ7wNUntO2OXfmJ:D8a9sPuBSor3NUcjXeJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b0251b4f4f64656d |
|
VISUAL
aHash
|
00ffc3ffffffffef |
|
VISUAL
dHash
|
d610961600b0b49e |
|
VISUAL
wHash
|
00c3c3ffffff0000 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
9e16960004b0969e,0000400020004000,0010083032300810 |
• Threat: Financial Phishing
• Target: BNDES users
• Method: Impersonation to collect lead data
• Exfil: JavaScript based submission
• Indicators: New domain, obfuscated code
• Risk: High
Uses a 'loan simulator' funnel to trick users into entering business and contact details for illicit solicitation.
Mimics the visual identity of BNDES to establish false trust.