Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14DE32C303359793E95A347D2E1AA332572BE831ED50F8C14B3A8D5AA13D9C4A6533FD8 |
|
CONTENT
ssdeep
|
3072:/WVSOKnWYcu0d3yeHs54olu0d3yeHs54oxURX8VMAIGvnAK1toF:uIMzNvnAK1toF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c34bb87bba0ac3c2 |
|
VISUAL
aHash
|
ff002000000000ff |
|
VISUAL
dHash
|
0bc8c8ccc8c8a794 |
|
VISUAL
wHash
|
ff0078240060ffff |
|
VISUAL
colorHash
|
31406000000 |
|
VISUAL
cropResistant
|
000b4b4b4b2b0b14,b5b580048000001a,31c8c8cce8c843b6 |
• Amenaza: Phishing de credenciales financieras
• Objetivo: Inversores bancarios/cripto
• Método: Interfaz bancaria engañosa
• Exfil: Inyección JS ofuscada
• Indicadores: Código JS ofuscado
• Riesgo: Alto
The site uses a fake banking interface to capture user credentials when they attempt to 'Log In'.
Uses string manipulation functions to obfuscate the JS-based form submission logic to evade static analysis.