Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19CE229B49230D335B1C24BE8DA6425287A5FE1DCD7C695B4E388AF51B0D6CECD9260CB |
|
CONTENT
ssdeep
|
384:4r/aMJgua8uRhiXkdvNTDhPhLxeAxeDWNW1Tp34PxeeJEmuW3As+ONRW0Md:4r/aMJgushhPhleMeDGCSPxeeWmHxW |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f02317fc6e034b4e |
|
VISUAL
aHash
|
806660f0d8dede10 |
|
VISUAL
dHash
|
5cdcda93b1b4ac21 |
|
VISUAL
wHash
|
80466ef0d8dedf90 |
|
VISUAL
colorHash
|
38001000c40 |
|
VISUAL
cropResistant
|
b62c69c89081020c,5cdcda93b1b4ac21 |
• Amenaza: Phishing
• Objetivo: Credenciales de usuario
• Método: Sitio web malicioso usando ingeniería social para recopilar datos
• Exfil: wss://gambler-work.com/api/ws
• Indicadores: Dominio reciente, javascript ofuscado, formulario con campos sensibles
• Riesgo: ALTO
The site uses a form to collect email and password information, with the intention of harvesting login credentials.
Obfuscated Javascript is used to hide malicious behavior and/or payload.
User fills <input name='email'> → submitForm() → fetch('https://centvibe.com/api/submit') → exfiltrate credentials
User fills <input name='email'> → submitForm() → fetch('https://centvibe.com/api/submit') → exfiltrate credentials
layout-2344be9881d79b44.jssubmitForm()sendData()fb_pixel_id
Pages with identical visual appearance (based on perceptual hash)