Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1514153318545C93B5693A6A49321DF2AB1D3C613CB0318A5B2F993ED9BD7D85CDD028C |
|
CONTENT
ssdeep
|
48:sHhHcpnifS6uM6hRx1fRYwiMucL+CDQyS:CaiS6uM6hIk+1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e6dc997174c43199 |
|
VISUAL
aHash
|
ffffe7c3c3c3e7e7 |
|
VISUAL
dHash
|
8c140c4d0e0e4c0c |
|
VISUAL
wHash
|
42c7c3c3c3c3e3c3 |
|
VISUAL
colorHash
|
07600006000 |
|
VISUAL
cropResistant
|
8c140c4d0e0e4c0c,100c32b2b2320c10,0929696577b4da5a |
โข Threat: Credential harvesting phishing kit.
โข Target: CMR Puntos users.
โข Method: Fake login form to steal credentials.
โข Exfil: Unknown data exfiltration point.
โข Indicators: Recently registered domain, obfuscated JavaScript, forms detected.
โข Risk: HIGH - Credential theft is imminent.
The phishing kit captures RUT (Chilean national ID) and internet Banking password (Clave Internet) via a fake login form. Data is likely exfiltrated in real-time to an attacker-controlled server for immediate account takeover.
The kit includes functionality to intercept one-time passwords (OTPs) sent via SMS or authentication apps, enabling bypass of two-factor authentication for CMR Puntos accounts.
JavaScript file with potential for credential exfiltration or dynamic payload delivery.
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. VICTIM RECEIVES PHISHING EMAIL โ
โ - Email mimics CMR Puntos branding โ
โ - Contains link to fake login page โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. VICTIM VISITS FAKE CMR PUNTOS SITE โ
โ - Fake page replicates legitimate Banking portal โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. CREDENTIAL HARVESTING โ
โ - Victim enters login credentials โ
โ - Data captured via fake form โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. DATA EXFILTRATION โ
โ - Credentials sent via HTTP POST โ
โ - Standard form submission to attacker server โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. VICTIM RECEIVES PHISHING EMAIL โ
โ - Email mimics CMR Puntos branding โ
โ - Contains link to fake login page โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. VICTIM VISITS FAKE CMR PUNTOS SITE โ
โ - Fake page replicates legitimate Banking portal โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. CREDENTIAL HARVESTING โ
โ - Victim enters login credentials โ
โ - Data captured via fake form โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. DATA EXFILTRATION โ
โ - Credentials sent via HTTP POST โ
โ - Standard form submission to attacker server โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Pages with identical visual appearance (based on perceptual hash)