Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T175F17832B047982A16A3C0E3B160BF0966D3E70ACB0A465AD5ED638A0FC7D75FE13515 |
|
CONTENT
ssdeep
|
192:nwj18dlKYz6buSEsRhrfhOlg+dKr8GyPEY:hdlKYwQsR5glg+wrAPEY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9dbf41e14161674d |
|
VISUAL
aHash
|
00ffffffffff0000 |
|
VISUAL
dHash
|
90202800100032d0 |
|
VISUAL
wHash
|
000080f000000000 |
|
VISUAL
colorHash
|
0f0000001c0 |
|
VISUAL
cropResistant
|
3020282000000000,20d0d0d0d0d0d0d0,3010b232e8d4c008 |
• Amenaza: Kit de phishing para robo de credenciales
• Objetivo: Clientes de America First Credit Union
• Método: Formulario falso que roba Pin Number y Mobile Phone
• Exfil: Posible exfiltración de datos a través de JavaScript ofuscado
• Indicadores: Dominio no coincide, ofuscación detectada, formularios para datos sensibles
• Riesgo: ALTO - Robo inmediato de credenciales
Found 2 other scans for this domain