Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18361E7B7E98446B27B53C1F0EAD9480C9702C9CDC7A311D2C9D4026E57A4DB7DC4A16C |
|
CONTENT
ssdeep
|
48:nY5bAVVd6jPJYoD/k6jPBrRV9FP1A2AFP5fJtWtFPMBiw9tKBTtw9t7Bsw9tKB7L:n909TBn9YLfqttw7qtw7qw7xqVB |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9999666666669999 |
|
VISUAL
aHash
|
0018181818180000 |
|
VISUAL
dHash
|
00b2b2b030301000 |
|
VISUAL
wHash
|
183c3c3c3c3c3c00 |
|
VISUAL
colorHash
|
38000000c00 |
|
VISUAL
cropResistant
|
cc0a4848484fcee0,00b2b2b030301000 |
β’ Threat: Possible redirection to a potentially malicious link.
β’ Target: Users of Yam Share service
β’ Method: Automatic redirection after a countdown
β’ Exfil: No direct exfiltration detected, but potential redirection to a malicious site.
β’ Indicators: Link shortener domain with auto redirection. The destination domain looks suspicious.
β’ Risk: LOW - Redirection to a possibly unsafe location.
The phishing kit employs form fields to capture user credentials in real-time. Submitted data is likely exfiltrated to a remote server controlled by the attacker, enabling account takeover or identity theft.
Additional forms may be designed to harvest personally identifiable information (PII) such as names, addresses, or phone numbers, which can be used for further social engineering or sold on dark web marketplaces.
Highly obfuscated JavaScript file with potential for credential harvesting or malicious payload delivery.
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β 1. VICTIM RECEIVES PHISHING LURE β
β - Fake email/SMS impersonating Yam Banking β
β - Contains link to fraudulent login page β
ββββββββββββββββββββββ¬ββββββββββββββββββββββββββββββββββββββ
β
βΌ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β 2. VICTIM VISITS FAKE YAM SITE β
β - Loads spoofed Banking portal β
β - Displays convincing login interface β
ββββββββββββββββββββββ¬ββββββββββββββββββββββββββββββββββββββ
β
βΌ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β 3. CREDENTIAL SUBMISSION β
β - Victim enters Banking credentials β
β - Form captures input data β
ββββββββββββββββββββββ¬ββββββββββββββββββββββββββββββββββββββ
β
βΌ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β 4. DATA EXFILTRATION β
β - Credentials sent via HTTP POST β
β - Standard form submission to attacker server β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β 1. VICTIM RECEIVES PHISHING LURE β
β - Fake email/SMS impersonating Yam Banking β
β - Contains link to fraudulent login page β
ββββββββββββββββββββββ¬ββββββββββββββββββββββββββββββββββββββ
β
βΌ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β 2. VICTIM VISITS FAKE YAM SITE β
β - Loads spoofed Banking portal β
β - Displays convincing login interface β
ββββββββββββββββββββββ¬ββββββββββββββββββββββββββββββββββββββ
β
βΌ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β 3. CREDENTIAL SUBMISSION β
β - Victim enters Banking credentials β
β - Form captures input data β
ββββββββββββββββββββββ¬ββββββββββββββββββββββββββββββββββββββ
β
βΌ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β 4. DATA EXFILTRATION β
β - Credentials sent via HTTP POST β
β - Standard form submission to attacker server β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain