Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C013C83108856F3B51A3D3CDA3605F0BE395858CE2B68589F5EAC31B66C4D95C82FF98 |
|
CONTENT
ssdeep
|
768:7LtH1CiIBC4q0slzm9akVNQaHYerDHYfXGO/Y0ltUShVvnUgYs1o4sF39yn:7L11CiIB5qZlzm9aEzYEHYf2O/NlJfXL |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9416eb4acbba9496 |
|
VISUAL
aHash
|
fd0006060600ffff |
|
VISUAL
dHash
|
61ccecccecec1933 |
|
VISUAL
wHash
|
ff0006060606ffff |
|
VISUAL
colorHash
|
130000001c0 |
|
VISUAL
cropResistant
|
002149616149014a,96d6e8b094710f8e,e0181a5b2c3b3313,ccccecccccecece0 |
• Amenaza: Phishing
• Objetivo: Inversores en criptomonedas
• Método: Envío de formulario para robar datos.
• Exfil: Desconocido (probablemente correo electrónico y teléfono, así como cualquier otro dato ingresado en el formulario)
• Indicadores: Nombre de dominio, formulario que solicita información personal y ofuscación.
• Riesgo: Alto
The site's primary attack method is credential harvesting, where attackers try to steal user's PII via a form for future attacks.
The information harvested may be used to launch spear-phishing attacks against the user, customized to the users' interests and connections.
Pages with identical visual appearance (based on perceptual hash)