Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D523B7659209B0620B7A4FF4A87D011712979D9FF8B2B4A09D26F7E634C3FF4AD5E108 |
|
CONTENT
ssdeep
|
768:aPthamDlsRDyYaBdNvQmfEMPyxEsiHqqZjispgNmzUmwtE+GnIWnIjiD99jifIAd:aPthDDKRDyYaBdNvQmfEMPyxEsiHqqZI |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b372cc815ccc99b9 |
|
VISUAL
aHash
|
efe7c7c4476fffff |
|
VISUAL
dHash
|
8c0f8d099d99ee36 |
|
VISUAL
wHash
|
67c7c1c0454f2fc3 |
|
VISUAL
colorHash
|
06200048040 |
|
VISUAL
cropResistant
|
8c0f8d099d99ee36,c749035cc0c51719,0008303232100800,0d070d0781d14d47 |
• Amenaza: Phishing
• Objetivo: Usuarios de Facebook
• Método: Suplantación de identidad a través de un dominio sospechoso y un formulario.
• Exfil: Probablemente roba credenciales de inicio de sesión
• Indicadores: Coincidencia de dominio, Ofuscación de Javascript, Envío de formulario.
• Riesgo: Alto
The site uses a form that collects the user's Facebook login credentials, which are then likely sent to a malicious server controlled by the attacker.
Pages with identical visual appearance (based on perceptual hash)