Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T194B342214557343722339F816AC4AB7D518B62D8A737CE07F6F44F2AAFC4E85A94C21E |
|
CONTENT
ssdeep
|
768:hZi4xAhMlQDXooCMki96jL0xZoHPfBEYzItxRnOE6:3i4xUDXooCriJxZoHPfqYzItvOE6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9964031b6f2b75ca |
|
VISUAL
aHash
|
00c0e2c09c0e1d3d |
|
VISUAL
dHash
|
d90c26063958d9c1 |
|
VISUAL
wHash
|
00e6f2e29c1f1d3b |
|
VISUAL
colorHash
|
0b400040002 |
|
VISUAL
cropResistant
|
f7eef9b0e1c22c7b,a5e6a0a3a7e3a1a1,3ed2989810154e4e,2fb46474ce87e666,313939585819d9c3,d9cd2606313859d1,33f3a3a1c3672758,d3d3c332ccd4d4d8 |
• Amenaza: Phishing
• Objetivo: Usuarios de Bradesco
• Método: Suplantación de dominio y ofuscación de JavaScript
• Exfil: Detectado pero no especificado
• Indicadores: Discordancia de dominio, ofuscación y envío de formulario
• Riesgo: Alto
The site likely attempts to steal user credentials by mimicking the Bradesco login page. When a user enters their information, the data is sent to the attacker.
The Javascript code is obfuscated to hide malicious functionality. It may contain a keylogger or other methods to steal the credentials.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain