Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B1818632934CAA7CD6C28B485625301936D5D5C9F266919CC7FF96479582DF0C8B48BC |
|
CONTENT
ssdeep
|
48:nwJV3BbSwyd41O66qJCtOfYxyfMlof5OxJXC9ofCH2HwfL8s8Ug8OmaYiepHN:nwf3p6ECYKyUlEiJXIoVHwVk4iW |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a226061b19ddcdcf |
|
VISUAL
aHash
|
0000f7cfffffffe7 |
|
VISUAL
dHash
|
fbcd27161002000c |
|
VISUAL
wHash
|
0000c3c3ffffff00 |
|
VISUAL
colorHash
|
070c00000c0 |
|
VISUAL
cropResistant
|
fbcd27161002000c |
• Amenaza: Phishing
• Objetivo: Clientes de Cembra
• Método: Suplantación de identidad a través de una página de inicio de sesión.
• Exfil: Datos del formulario
• Indicadores: Edad del dominio, discrepancia de dominio, formulario detectado.
• Riesgo: Alto
The attacker is attempting to steal user credentials by mimicking a legitimate login page. Users entering their username and password will have their credentials harvested.
Pages with identical visual appearance (based on perceptual hash)