Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T127E20E347003BC5B657396D1F862AF183646E736C2180F98B3E925BA6FDACF45862374 |
|
CONTENT
ssdeep
|
768:9vVYKlgNle0ldJYNuYATmbtwdQgNYTGAgWBujY5Lf5LfZLftLf2rCtTzhBeC3L:9vVYKlgNle0l3YNuYzbtwdNNYTGAgWBV |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b333333323cccccc |
|
VISUAL
aHash
|
e7e7ffeff7efe7ff |
|
VISUAL
dHash
|
4d4d000c0c0c0c0c |
|
VISUAL
wHash
|
0707272727272727 |
|
VISUAL
colorHash
|
07200038000 |
|
VISUAL
cropResistant
|
4d4d000c0c0c0c0c,7efcfefcfcfcf8f1 |
The phishing kit is designed to capture user credentials through fake login forms. The presence of a Credential Harvester kit suggests real-time interception and exfiltration of entered credentials via WebSocket or other communication channels.
The kit includes OTP Stealer and Card Stealer components, enabling the interception of one-time passwords and credit card details. This data is likely exfiltrated in real-time to an attacker-controlled server.
Large JavaScript file with high obfuscation, likely containing credential harvesting and data exfiltration logic.
Pages with identical visual appearance (based on perceptual hash)