Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T154B3E771F194303380174FE9FA78AE89A273F65ACF493556A6E8537423C7C71780AA6C |
|
CONTENT
ssdeep
|
1536:YX9cWQ7/lWQ2xfGXBTyQ7t3qHFC3rnW9sV9gpijcOMOgO8OEOoOMOIOMOFrje:SaWQ7/sQhTyQ7t5W9s8p0/e |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
88f3e698c29cc2bd |
|
VISUAL
aHash
|
ff00181818181918 |
|
VISUAL
dHash
|
71513333b33333f3 |
|
VISUAL
wHash
|
ff001899191f1f3e |
|
VISUAL
colorHash
|
01000000007 |
|
VISUAL
cropResistant
|
71513333b3333333,055dfdfdfdfde1fd,cc8e96eab2b22b82,a901110101010101,51333333b33333f0 |
• Amenaza: Phishing
• Objetivo: Clientes de T-Mobile
• Método: Imitación del portal de recompensas
• Exfil: Probablemente número de móvil. Potencialmente más datos a través de Javascript.
• Indicadores: Dominio sospechoso, dominio reciente, Javascript ofuscado y envío de formulario.
• Riesgo: ALTO
The site is designed to look like the T-Mobile rewards portal. It attempts to collect a mobile number, which can then be used in further phishing attacks, such as SMS phishing.
Malicious Javascript is injected into the site to steal data or redirect the user to a more dangerous page.
Pages with identical visual appearance (based on perceptual hash)
Found 5 other scans for this domain