Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1529354F61D148E3D01134E8AD6EBE318D389887DA9694C8BCAFF5B76418BD50F4A3C64 |
|
CONTENT
ssdeep
|
1536:ooxbc2UTtScI3bjiV+EAiHgJsNp+Iozji/beL39YiUiVJPVmCsUYuVkv63S7G21u:oAc2KK3DTWb6zlAh3Ps1KNPEc2wV0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a404eeee7b191393 |
|
VISUAL
aHash
|
13000600ffffffff |
|
VISUAL
dHash
|
57a7be9e051c140c |
|
VISUAL
wHash
|
00000e00e7ffffef |
|
VISUAL
colorHash
|
060020000c0 |
|
VISUAL
cropResistant
|
694447a7aafede9a,9390a4666b696926,8280a232b28280d8,821c45181404104c,0002010696064142,47a7aafe9e9aac90 |
• Amenaza: Phishing
• Objetivo: Departamento de Servicios para Conductores de Georgia (DDS)
• Método: Suplantación de identidad a través de un sitio web falso.
• Exfil: Envío de formularios a un servidor malicioso.
• Indicadores: Coincidencia de dominio, Javascript sospechoso.
• Riesgo: ALTO
The attackers are impersonating the Georgia Department of Driver Services by creating a website that looks similar to the official one.
The site uses a citation notice to trick the user into thinking there's a problem they need to address, prompting them to take action.
User fills <input name=email> → _0x54f69b() → fetch('/api/open/getSyncSet') → exfiltration to API endpoints
User fills <input name=email> → _0x54f69b() → fetch('/api/open/getSyncSet') → exfiltration to API endpoints
main.js_0x54f69b_0x56f3Pages with identical visual appearance (based on perceptual hash)