Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T135F251B09056AA3B02F392E0AB756B6FB3D5E2C8D943470516F8835D5FCBF94ED21092 |
|
CONTENT
ssdeep
|
384:cwJ7vZc+VW51az/CygUyD084mR8m9Q8lz/YBN5BnA8oA:cwpRc+Vu1aG1WQ8yVKLFoA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cf9a71218ec6ce8c |
|
VISUAL
aHash
|
00003c3c3c380000 |
|
VISUAL
dHash
|
4c9b616969631616 |
|
VISUAL
wHash
|
ff893d3c3cb8c0c0 |
|
VISUAL
colorHash
|
01000000e00 |
|
VISUAL
cropResistant
|
cc82155586664c46,4c9b616969631616 |
• Amenaza: Phishing
• Objetivo: Usuarios de Bet365
• Método: Suplantación a través de un sitio web similar.
• Exfil: Credenciales de usuario (probablemente).
• Indicadores: Dominio engañoso, javascript ofuscado, formulario de inicio de sesión.
• Riesgo: Alto
The attacker sets up a fake bet365 login page that collects user credentials (username and password) entered by unsuspecting victims. The form submits the data to a server controlled by the attacker.
Pages with identical visual appearance (based on perceptual hash)