Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11FE100E1D404ED37435286D9A7F66B4B76D2C349CE03194493F883AB5BDECA0CB22699 |
|
CONTENT
ssdeep
|
96:nkfA81DtSTBJ8v67oKSFtGeGlW2XyHFJSX/HF3yXp4/IRY3zEmSTyR:kfx1DcD8iitGUAo4QRgzEDk |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dc5c5cf673727200 |
|
VISUAL
aHash
|
001800ffffff0000 |
|
VISUAL
dHash
|
72b2320c00000000 |
|
VISUAL
wHash
|
001800ffffff0f00 |
|
VISUAL
colorHash
|
060000001c0 |
|
VISUAL
cropResistant
|
41a2a2a2a2a2a241,82a2a2a2a2a2a200,82a2b28c32b2b2b2,0000000000000000,4070b2b2b2b25428,0000000000000000 |
• Amenaza: Phishing
• Objetivo: No especificado
• Método: Recopilación de credenciales a través de formulario de inicio de sesión
• Exfil: https://dfrmnail.weebly.com/ajax/apps/formSubmitAjax.php
• Indicadores: Alojamiento gratuito, formulario, ofuscación
• Riesgo: Alto
The attacker attempts to steal user credentials by providing a fake login form and sending submitted data to a remote location.