Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F9B184621518919B12534EC2FFA37B4D32EBF22EDDA21D54D2FE839C4ADBDC5C429812 |
|
CONTENT
ssdeep
|
96:non9C9uKs36I0UQXifzzaTDUTrT+2GuYsClRlKhzLo6ET:ys9fSQX0YuHBYsYoBEj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b2333e7b35c82394 |
|
VISUAL
aHash
|
0707070707070f0f |
|
VISUAL
dHash
|
2dadbdbdbcfdbd3c |
|
VISUAL
wHash
|
07070f0f0f0f1f1f |
|
VISUAL
colorHash
|
0b0002000c0 |
|
VISUAL
cropResistant
|
8e96968eb89696c0,9e9e9e96de9e9efe,acdecace6e6e4e2e |
• Amenaza: Potencial recolección de datos.
• Objetivo: Usuarios de Titan Trade.
• Método: Formulario de inicio de sesión.
• Exfil: Envío de datos al servidor.
• Indicadores: El dominio contiene el nombre de la marca.
• Riesgo: BAJO - Página de inicio de sesión plausible. Se necesita más investigación de Titan Trade y el dominio para verificar la legitimidad.
The phishing page presents a fake login form for Titan Trade, capturing email and password inputs in real-time. Submitted credentials are likely exfiltrated to an attacker-controlled server for immediate use in account takeover attacks.
The kit includes modules for intercepting one-time passwords (OTPs) and credit card details. After capturing initial credentials, the page may dynamically request additional sensitive information under the guise of 'verification' or 'security checks'.
Large JavaScript file containing obfuscated credential harvesting and data exfiltration logic.
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING EMAIL │
│ - Email mimics Titan Trade branding │
│ - Contains link to fake login page │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM VISITS FAKE TITAN TRADE SITE │
│ - Page replicates legitimate Banking portal │
│ - Displays convincing login form │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL SUBMISSION │
│ - Victim enters Banking credentials │
│ - Form appears identical to real site │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. CREDENTIAL EXFILTRATION │
│ - Data sent via HTTP POST (standard form submission) │
│ - Transmitted to attacker-controlled server │
└──────────────────────────────────────────────────────────┘
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING EMAIL │
│ - Email mimics Titan Trade branding │
│ - Contains link to fake login page │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM VISITS FAKE TITAN TRADE SITE │
│ - Page replicates legitimate Banking portal │
│ - Displays convincing login form │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL SUBMISSION │
│ - Victim enters Banking credentials │
│ - Form appears identical to real site │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. CREDENTIAL EXFILTRATION │
│ - Data sent via HTTP POST (standard form submission) │
│ - Transmitted to attacker-controlled server │
└──────────────────────────────────────────────────────────┘
Pages with identical visual appearance (based on perceptual hash)