Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E6A151E13899453E33F746CAF0A2AB5830CA5659C441B408D59117FD07D9EA5DCCE31F |
|
CONTENT
ssdeep
|
96:M6aVeiJ3VI0wVWdAXF2k8lc43rIjfeb1GmcoGkGcGBavG61GEOG0K1GY4tVM1GYN:EFsWd4FLsc451GmVGkGcGO1GEOGN1GYh |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b326790cd986f326 |
|
VISUAL
aHash
|
000000ffffffffff |
|
VISUAL
dHash
|
8c2849320c10041b |
|
VISUAL
wHash
|
000000ffcfcf89ff |
|
VISUAL
colorHash
|
07e00000000 |
|
VISUAL
cropResistant
|
8c2849320c10041b |
• Amenaza: Suplantación de identidad
• Objetivo: Usuarios de Mercado Libre
• Método: Recopilación de credenciales (potencial)
• Exfil: Desconocido (potencialmente a través de JS)
• Indicadores: Dominio inusual, ofuscación de JavaScript.
• Riesgo: Moderado
The site likely aims to trick users into entering their Mercado Libre credentials on a fake login page. The obfuscated Javascript may be used to intercept or manipulate this data.
The site may redirect the user to a more elaborate phishing campaign.
client-cookies-agent.min.jsPages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain