Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T121A3FD234229762B4437C3C130695B3BD1A69A8FFEE709405EDCC7F62AFACA0741E559 |
|
CONTENT
ssdeep
|
1536:hnttpR4nXBKpSpFl26vpjbGgQ+NWWDIQ9:LUMEjbGgQ+NWWDIQ9 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93136d03d3137d2d |
|
VISUAL
aHash
|
001f0f2e3e0f01ff |
|
VISUAL
dHash
|
dcbf3cdcdcbcf700 |
|
VISUAL
wHash
|
00070f3f3f0f01ff |
|
VISUAL
colorHash
|
00003400400 |
|
VISUAL
cropResistant
|
fdb75cdcd8bdf700,dcbd7cdcdc38b73f,9bbb1b996227abc9,68000832320c21d4 |
• Amenaza: Phishing
• Objetivo: Usuarios desprevenidos
• Método: Robo de datos basado en formularios
• Exfil: https://the-dinhexgpt.com/assets/submit.php
• Indicadores: Dominio sospechoso, solicitud de información personal, ofuscación JavaScript, envíos de formularios.
• Riesgo: ALTO
The attackers are attempting to steal user credentials (name and email) by using a form designed to look legitimate. The stolen credentials can then be used for identity theft or other malicious activities.
Pages with identical visual appearance (based on perceptual hash)