Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T113939A23412965274477C2C1347A6B3BD1E6D99BFAE70A014EECCBFA2BF9C90741B119 |
|
CONTENT
ssdeep
|
768:xv6uStpR4nXF6YjOpSpFlTC6rrW/DdD4Qe4XPt0lsDtu:xv69tpR4nXBKpSpFl26vsVC8Pt0lWtu |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8339fcc6ea1c9163 |
|
VISUAL
aHash
|
ff000e2e7c7e00ff |
|
VISUAL
dHash
|
c8cfd8e8ccec6c83 |
|
VISUAL
wHash
|
fe000e0c7c7e04ff |
|
VISUAL
colorHash
|
11006000040 |
|
VISUAL
cropResistant
|
b494e8cc829692f6,d500000000000000,c8c7d8f8ccccec6d |
• Amenaza: Phishing
• Objetivo: Usuarios que buscan servicios financieros
• Método: Suplantación de identidad y recopilación de datos a través de un formulario.
• Exfil: https://thezentroforgelink.com/assets/submit.php
• Indicadores: Nombre de dominio, formulario con solicitud de datos personales, Obfuscación de JavaScript
• Riesgo: ALTO
The attacker is attempting to collect user data, such as first name, last name, and email address by utilizing a form and submitting that to a different php endpoint.
The use of JavaScript may be designed to exfiltrate data from this site.
Pages with identical visual appearance (based on perceptual hash)