Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FB22B76190AA5D3F021782E8ABEA7F1367A7C746C6D20129C2FD97CD0FE9D50DA13528 |
|
CONTENT
ssdeep
|
192:nntKc1WzPnSMnRumGqnR4Y06GY4tc4t7es73o2hH:ntne//nRumGqnR4Y06GnV1ZzoeH |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b5338ac86cbc9c47 |
|
VISUAL
aHash
|
ff62020242ffffff |
|
VISUAL
dHash
|
c0ca4e5686a00600 |
|
VISUAL
wHash
|
7f00020000ffffff |
|
VISUAL
colorHash
|
07c00008000 |
|
VISUAL
cropResistant
|
c0ca4e5686a00600,23c5196380000212 |
• Amenaza: Phishing
• Objetivo: Usuarios de SwissPass
• Método: Recopilación de credenciales
• Exfil: princecorona/getlog.php
• Indicadores: Discordancia de dominio, acción de formulario sospechosa.
• Riesgo: ALTO
The attacker aims to steal user credentials (email and password) by mimicking the login page of SwissPass.ch. The form action is set to a malicious script, which will receive and store user data.
Pages with identical visual appearance (based on perceptual hash)