Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14343D7F0A165A67B019BB2D3B739AB1E26D2870AD64747E0D2FC836C1BD5D50DD3B028 |
|
CONTENT
ssdeep
|
1536:dxvGd6C8BH1lnfK0Th+OG9GC3X3Y0eGC+pma6M:bvGdA3DaSM |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cb6564129cc76799 |
|
VISUAL
aHash
|
00203c3c3c3c3c38 |
|
VISUAL
dHash
|
4948506171696960 |
|
VISUAL
wHash
|
243c3c3c3c3c3e3e |
|
VISUAL
colorHash
|
08007000000 |
|
VISUAL
cropResistant
|
37367afaf0c2e3e3,4948506171696960 |
โข Threat: Potential distribution of malicious Workshop content.
โข Target: Steam users interested in Team Fortress 2.
โข Method: Distribution of a modified game asset through the Steam Workshop.
โข Exfil: N/A
โข Indicators: Workshop content available on Steam.
โข Risk: LOW - risk of potential malware if Workshop item is malicious.
The phishing kit captures Steam account credentials via fake login forms. Input fields are intercepted in real-time and exfiltrated to attacker-controlled servers, enabling immediate account takeover.
Secondary forms target one-time passwords (OTP) and payment card details, likely using fake authentication prompts or transaction verification pages to trick victims into submitting sensitive data.
Large JavaScript file with advanced obfuscation, likely used for credential and payment data interception.
Pages with identical visual appearance (based on perceptual hash)