Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B5618561804DA86FC2534881F627BA15A147441E8B538E963FA5C696FDCAD32DE313CE |
|
CONTENT
ssdeep
|
96:cSVkC3VSuNSadcadaamUadavadasBsDBSZBijB7ne:jVkCtIwcwhmUwmw7+Re |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
eb79c4846b7a3826 |
|
VISUAL
aHash
|
c2ff818181ffffff |
|
VISUAL
dHash
|
16d61b3b63134d0d |
|
VISUAL
wHash
|
c0da818101ffe7e7 |
|
VISUAL
colorHash
|
07000400049 |
|
VISUAL
cropResistant
|
16d61b3b63134d0d,2d2d929292d27065,66aaca4a2a2aaa66,0f3371696971310f,0f71616969696969,0f3371696971310f,33f5c4653594b567,6969713313061d3a,0000101010100800 |
• Amenaza: Phishing
• Objetivo: Clientes de YONO SBI
• Método: Suplantación e ingeniería social
• Exfil: Probablemente credenciales de cuenta e información financiera.
• Indicadores: Dominio no relacionado, urgencia y ofertas de recompensas.
• Riesgo: ALTO
The phishing site attempts to steal the user's login credentials by providing a fake login form that mimics the appearance of the YONO SBI login portal. Once the user enters their username and password, the attackers gain access to the account.
The attackers leverage social engineering techniques like the promise of rewards and the need to complete KYC to create a sense of urgency and convince users to submit their credentials.
Pages with identical visual appearance (based on perceptual hash)