Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BAA30C234169752B4437C2D034AA5F3BE1A69D9FFAE70A004EDCC7F76AF9CA0741A119 |
|
CONTENT
ssdeep
|
768:tB5J4EtpR4nXF6YjOpSpFlTC6rrs3/361yf5wF24kuz1mH:9tpR4nXBKpSpFl26vm/3i924/kH |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9340ec3fead097b0 |
|
VISUAL
aHash
|
ff000e0e0e0e0eff |
|
VISUAL
dHash
|
23d8dc58585858a3 |
|
VISUAL
wHash
|
ff080e0e0e0e0eff |
|
VISUAL
colorHash
|
03000038000 |
|
VISUAL
cropResistant
|
23d8dc58585858a3,0042401100002606,81630d0923074705,7d7f7f67735f6e1d |
• Amenaza: Phishing
• Objetivo: Usuarios desprevenidos
• Método: Robo de datos basado en formularios
• Exfil: https://thefluxorbeam-ai.org/assets/submit.php
• Indicadores: JS ofuscado, Formulario, Edad del dominio
• Riesgo: Medio
The site uses a form to collect personal information (name, email). This data is then sent to a PHP script. This allows attackers to potentially harvest user data for various purposes, including identity theft and targeted phishing attacks. The obfuscated Javascript likely attempts to evade detection and/or manipulate the captured data before exfiltration.
Obfuscation can be used to hide malicious Javascript that will gather more data from the user and send it to the attacker.
Pages with identical visual appearance (based on perceptual hash)