Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B2A3EE234169752B4437C7C1306A5B3BE1A6998FFEFB0A405EDCC7FA2AF9C90741A119 |
|
CONTENT
ssdeep
|
1536:AJqtpR4nXBKpSpFl26vmGLZcQOWnWDYSSw8:9UM5GLZcQOWnWDYSSw8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93076d0353177f0d |
|
VISUAL
aHash
|
001f0f3e6f0f01c7 |
|
VISUAL
dHash
|
dcbf3cdcdcb8b30f |
|
VISUAL
wHash
|
000f0f3f7f0f01e7 |
|
VISUAL
colorHash
|
00003400400 |
|
VISUAL
cropResistant
|
fdb77cdcdcb9f30f,dcbd3cdcdcfcbb77,c6d60c981b1c495a,48d9a9676168cac8,6e878b85a7a7ae8d,68100c32320c21d4 |
• Amenaza: Phishing
• Objetivo: Usuarios de Neuroverde Prime AI (o potenciales usuarios)
• Método: Engaño a través de un formulario de inicio de sesión falso
• Exfil: https://neuroverdeprimeai-today.com/assets/submit.php
• Indicadores: Antigüedad del dominio, ofuscación, envíos de formulario
• Riesgo: Alto
The attacker attempts to steal user credentials (name, email and phone number) via a fake form.
The attacker employs Javascript obfuscation to hide and potentially execute malicious code. This helps to evade detection.
Pages with identical visual appearance (based on perceptual hash)