Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BE13D83158C46B7B02C383D15364AE1BF3E69284E27ACB0AF6E6935B56C4D54CC37A6C |
|
CONTENT
ssdeep
|
768:oxZdXsWI7xkndBsN8gfxzzke0w5kAKRYVkT6wsNGw3fCcEDON5nGTPDLSnQMHFJZ:oxXcnwBE15n2w+AKRokT61NGwPCinGLK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
944be9948eb4e2cb |
|
VISUAL
aHash
|
ff000016360606ff |
|
VISUAL
dHash
|
71f1ecececac8c31 |
|
VISUAL
wHash
|
ff000636366606ff |
|
VISUAL
colorHash
|
03000000038 |
|
VISUAL
cropResistant
|
0001416363c50004,2428787858787878,96d6e8b0904d0f8e,f8f8b8f8e92c3c68,00000034347c012d,32d0ececece4ac8c |
• Amenaza: Phishing de suplantación.
• Objetivo: Usuarios interesados en Oil Evex Pro.
• Método: Formularios para robar credenciales.
• Exfil: Datos ingresados por el usuario.
• Indicadores: Formulario de creación de cuenta, tema de plataforma de trading, JS ofuscado.
• Riesgo: Alto
The attacker aims to steal user credentials (username, password) by luring them into entering this information into a fake form that closely resembles the legitimate login page of Oil Evex Pro.
Obfuscated Javascript can be used to redirect the user to a different site, steal entered data, or redirect to a more sophisticated phishing page. This can lead to further attacks.
Pages with identical visual appearance (based on perceptual hash)