Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15D52E97101006E3F82C586D8E2B9770B3682C2D7C6464784D3F5879FADD9DE2DC2AA9D |
|
CONTENT
ssdeep
|
192:LFqGYXIjJFLJHAlm121lBVxlWxab1Wgl48qlBbtaH/G6os+NJHAlm125lBV/lWxj:LFnSWmRRx91bqm9R/91Vy |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ece4339966329933 |
|
VISUAL
aHash
|
ffdbc3d352180000 |
|
VISUAL
dHash
|
96969696b6b21212 |
|
VISUAL
wHash
|
ffdbdbd3d3180000 |
|
VISUAL
colorHash
|
38000000e00 |
|
VISUAL
cropResistant
|
96969696b6b21212 |
• Amenaza: Phishing
• Objetivo: Usuarios de Spotify
• Método: Suplantación de identidad mediante una página de inicio de sesión falsa.
• Exfil: login.php (basado en acciones del formulario)
• Indicadores: Dominio no relacionado, formulario presente, código ofuscado.
• Riesgo: ALTO
The attackers are using a fake Spotify login page hosted on a different domain (eat-co.com) to steal user credentials. Users are tricked into entering their login information, which is then sent to the attackers.