Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DEA3EE234259752A4477C3D430AA1F3BD1BA994BFAE709400EDCC7F62BFAC94702B659 |
|
CONTENT
ssdeep
|
768:0Ng9tMbXReQ/GJi55RPGOrboE/iF/uas1qcnD:r9tMbXlOJi55R+OvoE/iF7s1qcnD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9612ed690d6f1693 |
|
VISUAL
aHash
|
00040e060600ffff |
|
VISUAL
dHash
|
d77cecccbc0c0326 |
|
VISUAL
wHash
|
000e0e0e0e8effff |
|
VISUAL
colorHash
|
02003400400 |
|
VISUAL
cropResistant
|
bc6cecccbc0c0026,dcbd6cececccac7c,1c07432513161c3c |
• Amenaza: Phishing
• Objetivo: Usuarios desprevenidos
• Método: Recopilación de credenciales
• Exfil: Desconocido (envío de formulario)
• Indicadores: Formulario, Javascript, ofuscación, dominio nuevo
• Riesgo: ALTO
The site uses a form to collect user data (email, name) which is then sent to an unknown location, likely for misuse (phishing/spam or identity theft)
The site's JavaScript, especially considering the obfuscation, may be designed to install or redirect to a malicious script.
Pages with identical visual appearance (based on perceptual hash)