Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F803B8B052045A3DA143C3ECD732377A32BA91D5EB0B121AC6F857789A85CDAEC375D8 |
|
CONTENT
ssdeep
|
384:ysKQsWsr1S96KtpWKnP0bDhT1Pyt/wFKBKcxjmLAvgu3KR4X4+BTgAZK:yjQDaiL0bD/cwFUsRCj1K |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cccccc6633333399 |
|
VISUAL
aHash
|
005a180000000000 |
|
VISUAL
dHash
|
0030100000000000 |
|
VISUAL
wHash
|
ffffffff00000000 |
|
VISUAL
colorHash
|
38000000000 |
|
VISUAL
cropResistant
|
0030100000000000 |
• Amenaza: Phishing por suplantación
• Objetivo: Usuarios de X/Twitter
• Método: Mostrar un mensaje de verificación falso y posiblemente solicitar credenciales.
• Exfil: Desconocido, probablemente robar credenciales
• Indicadores: Dominio no relacionado con X, suplantación de marca, código ofuscado
• Riesgo: Alto
The site impersonates X/Twitter and displays a 'verification complete' message. This can lull users into a false sense of security, possibly followed by a redirect to a login form that harvests credentials.
The site uses Javascript obfuscation to hide potentially malicious actions like credential harvesting.
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain