Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19BF251B09056AA3B02F392E0AB756B6FB3D5E2C8D54347051AF8835D5FCBF94ED21092 |
|
CONTENT
ssdeep
|
384:cw3VZc+VWTaz/CygUyD084mR8m9Q8lz/YBN5BnA8oA:cwfc+V4aG1WQ8yVKLFoA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cf9a71218ec6ce8c |
|
VISUAL
aHash
|
00003c3c3c380000 |
|
VISUAL
dHash
|
4c9b616969631616 |
|
VISUAL
wHash
|
ff893d3c3cb8c0c0 |
|
VISUAL
colorHash
|
01000000e00 |
|
VISUAL
cropResistant
|
cc82155586664c46,4c9b616969631616 |
• Amenaza: Phishing
• Objetivo: Usuarios de Bet365
• Método: Suplantación de dominio y envío de formulario
• Exfil: /login_action
• Indicadores: Coincidencia de dominio, ofuscación, formularios
• Riesgo: Alto
The attacker uses a fake login form to steal users' usernames and passwords.
Hides the malicious behaviour, making it harder to detect.
Pages with identical visual appearance (based on perceptual hash)