Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B8E229B4A230D335B1C247E8DA6425687A5FE1DCD7C695B4F388AF11B0D6CE8D5260CB |
|
CONTENT
ssdeep
|
384:4rAneu0TPRhiXkdvNTDhPhLxeAxeDWNW1Tp34PxeeJEmuW3AskoRWeMd:4rAneuahhPhleMeDGCSPxeeWmHBW |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d1633ebc681f1c68 |
|
VISUAL
aHash
|
806660f0f8de8e00 |
|
VISUAL
dHash
|
5cdcdad391346c31 |
|
VISUAL
wHash
|
806626f0f8debf90 |
|
VISUAL
colorHash
|
38018000600 |
|
VISUAL
cropResistant
|
d0f066a63936e0f2,f8b2b4c192c6c5ce,00100c4c4c0c1008,5cdcdad391346c31 |
• Amenaza: Robo de credenciales
• Objetivo: Usuarios desprevenidos
• Método: Engaño a través de un formulario de registro falso.
• Exfil: wss://gambler-work.com/api/ws (WebSocket URL)
• Indicadores: Formulario de registro, imagen de celebridad, reclamo de recompensa gratuita, javascript obfuscado.
• Riesgo: ALTO
The site utilizes a registration form to collect user email addresses and passwords, with the likely intent of stealing those credentials and gaining access to user accounts.
The site uses visual elements (celebrity endorsement) and incentives like 'free reward' to encourage users to enter their credentials. This aims to bypass user's security awareness
fbevents.jsPages with identical visual appearance (based on perceptual hash)