Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A301D0120001ECB2C5A1F5B09391990116D6C724CB971800A7FCD7ED3AF5CADCD875A9 |
|
CONTENT
ssdeep
|
12:nwMy7F8L1PZLEIzicYuPKH833YPKHPf35cElBcjGuuRStGuaHWgTK5V5XKkgFp1F:n/CcVZLvzFJvxcElB4oS723F/N |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
888c6c7367367a33 |
|
VISUAL
aHash
|
10391c3e7c581c01 |
|
VISUAL
dHash
|
e57370f4d9b9e8b1 |
|
VISUAL
wHash
|
103d3f3e7c783c41 |
|
VISUAL
colorHash
|
06e00000040 |
|
VISUAL
cropResistant
|
637360d491b1e8b1,999323ab2bf868e8,8ebc94d9786689d0,e57370f4d9b9e8b1,c3c3e56522f153ca |
โข Threat: Credential harvesting phishing attack targeting Chase customers.
โข Target: Chase bank customers.
โข Method: A fake Chase login page attempts to steal usernames and passwords.
โข Exfil: Stolen data is sent to a Telegram bot using the token 7897438235:AAHp5zT-bVKW6N1hrIGEWRjtzBorp-4fBck.
โข Indicators: Suspicious domain name, use of PHP for form submission, obfuscated JavaScript, and a Telegram bot token indicating data exfiltration.
โข Risk: CRITICAL - Real-time credential theft is highly likely.
The phishing page presents a fake Chase Bank login form with fields for 'Username' and 'Password'. Submitted credentials are intercepted in real-time via JavaScript and exfiltrated to a Telegram bot controlled by the attacker.
Detected Telegram bot integration enables immediate transmission of harvested credentials to the attacker, reducing the window for victim remediation.
| ID | Portuguese | English | Trigger |
|---|---|---|---|
Contains credential harvesting logic and Telegram bot integration for real-time exfiltration.
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. VICTIM RECEIVES PHISHING LURE โ
โ - Email/SMS with fake Chase alert โ
โ - Link to spoofed Chase login page โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. FAKE LOGIN PAGE LOADING โ
โ - Victim lands on Chase-branded phishing site โ
โ - Displays urgent security message โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. CREDENTIAL SUBMISSION โ
โ - Victim enters Banking credentials โ
โ - Form captures input without validation โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. DATA EXFILTRATION โ
โ - Stolen credentials sent to Telegram bot โ
โ - Single token used for communication โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. VICTIM RECEIVES PHISHING LURE โ
โ - Email/SMS with fake Chase alert โ
โ - Link to spoofed Chase login page โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. FAKE LOGIN PAGE LOADING โ
โ - Victim lands on Chase-branded phishing site โ
โ - Displays urgent security message โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. CREDENTIAL SUBMISSION โ
โ - Victim enters Banking credentials โ
โ - Form captures input without validation โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. DATA EXFILTRATION โ
โ - Stolen credentials sent to Telegram bot โ
โ - Single token used for communication โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Pages with identical visual appearance (based on perceptual hash)