Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14343D7F0A165A67B019BB2D3B739AB1E26D2870AD64747E0D2FC836C1BD5D50DD3B028 |
|
CONTENT
ssdeep
|
1536:dxvGd6C8BH1lnfK0Th+OG9GC3X3Y0eGC+pma6M:bvGdA3DaSM |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cb6564129cc76799 |
|
VISUAL
aHash
|
00203c3c3c3c3c38 |
|
VISUAL
dHash
|
4948506171696960 |
|
VISUAL
wHash
|
243c3c3c3c3c3e3e |
|
VISUAL
colorHash
|
08007000000 |
|
VISUAL
cropResistant
|
37367afaf0c2e3e3,4948506171696960 |
• Amenaza: Potencial distribución de contenido malicioso en el Workshop.
• Objetivo: Usuarios de Steam interesados en Team Fortress 2.
• Método: Distribución de un activo de juego modificado a través del Steam Workshop.
• Exfil: N/A
• Indicators: Contenido de Workshop disponible en Steam.
• Risk: BAJO - Riesgo potencial de malware si el artículo del Workshop es malicioso.
The phishing kit captures Steam account credentials via fake login forms. Input fields are intercepted in real-time and exfiltrated to attacker-controlled servers, enabling immediate account takeover.
Secondary forms target one-time passwords (OTP) and payment card details, likely using fake authentication prompts or transaction verification pages to trick victims into submitting sensitive data.
Large JavaScript file with advanced obfuscation, likely used for credential and payment data interception.
Pages with identical visual appearance (based on perceptual hash)