Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T156834631D367181390AFD2D4B171474923928789CA134BB967FD63BAFACDCB53623298 |
|
CONTENT
ssdeep
|
1536:e11DXgyeeMXehXexiPUgOq61e61tICbe9E8eeYdqNirQCcrW+SfbMP3+0fHonzHX:V2FPUgOq6NL5ukJRk222I2222222dsXu |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b2cdc73930938ccd |
|
VISUAL
aHash
|
fff17f46c1c147c5 |
|
VISUAL
dHash
|
c0e7e48c8d8d8c8d |
|
VISUAL
wHash
|
fff17e4645404645 |
|
VISUAL
colorHash
|
02200038000 |
|
VISUAL
cropResistant
|
c0e7e48c8d8d8c8d,9192b2b0a9a0a2f2,01d924f035172b2b,d7693248cccc452c,676d4f7747597b23,9793d6c469239171,4753713c30504061 |
• Amenaza: Phishing
• Objetivo: Usuarios de Shopee
• Método: Suplantación de identidad mediante sorteo
• Exfil: Probablemente roba información personal si el usuario interactúa con el sitio. La presencia de javascript ofuscado hace que el propósito real no esté claro.
• Indicadores: Dominio no coincidente, tema de sorteo, ofuscación.
• Riesgo: Alto
The attackers are mimicking the appearance of Shopee to deceive users into providing personal information or clicking malicious links.
The site uses a giveaway to entice users into interacting with the fake site.
Pages with identical visual appearance (based on perceptual hash)