Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14FF36238A300053E55574BE8F3E4A33C51BAE388DA17891DB67C01A21BC7EE5EE67794 |
|
CONTENT
ssdeep
|
1536:bxUIkBpoLojuqjV3U3uPHwzFa0zn/ztodfXmsBhK6yr:bxSBWUfXmsBoNr |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c1e73c3cc7e1301e |
|
VISUAL
aHash
|
020c7c7c7c4c0c0c |
|
VISUAL
dHash
|
c678c8c8e898d878 |
|
VISUAL
wHash
|
420c7e7c7c7c3c1c |
|
VISUAL
colorHash
|
30000000e00 |
|
VISUAL
cropResistant
|
c678c8c8e898d878 |
• Amenaza: Recolección de credenciales financieras
• Objetivo: Usuarios de DA Markets
• Método: Suplantación de plataforma de trading
• Exfil: Envío de formularios mediante JavaScript
• Indicadores: Código fuente ofuscado
• Riesgo: Alto (Robo financiero)
The site mimics a legitimate broker platform to trick users into entering personal and banking data.
Uses obfuscated JS to intercept form submissions and send them to an external server.