Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A301D0120001ECB2C5A1F5B09391990116D6C724CB971800A7FCD7ED3AF5CADCD875A9 |
|
CONTENT
ssdeep
|
12:nwMy7F8L1PZLEIzicYuPKH833YPKHPf35cElBcjGuuRStGuaHWgTK5V5XKkgFp1F:n/CcVZLvzFJvxcElB4oS723F/N |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
888c6c7367367a33 |
|
VISUAL
aHash
|
10391c3e7c581c01 |
|
VISUAL
dHash
|
e57370f4d9b9e8b1 |
|
VISUAL
wHash
|
103d3f3e7c783c41 |
|
VISUAL
colorHash
|
06e00000040 |
|
VISUAL
cropResistant
|
637360d491b1e8b1,999323ab2bf868e8,8ebc94d9786689d0,e57370f4d9b9e8b1,c3c3e56522f153ca |
• Amenaza: Ataque de phishing para la recolección de credenciales dirigido a clientes de Chase.
• Objetivo: Clientes del banco Chase.
• Método: Una página de inicio de sesión falsa de Chase intenta robar nombres de usuario y contraseñas.
• Exfil: Los datos robados se envían a un bot de Telegram utilizando el token 7897438235:AAHp5zT-bVKW6N1hrIGEWRjtzBorp-4fBck.
• Indicadores: Nombre de dominio sospechoso, uso de PHP para el envío de formularios, JavaScript ofuscado y un token de bot de Telegram que indica la exfiltración de datos.
• Riesgo: CRÍTICO - Es muy probable el robo de credenciales en tiempo real.
The phishing page presents a fake Chase Bank login form with fields for 'Username' and 'Password'. Submitted credentials are intercepted in real-time via JavaScript and exfiltrated to a Telegram bot controlled by the attacker.
Detected Telegram bot integration enables immediate transmission of harvested credentials to the attacker, reducing the window for victim remediation.
| ID | Portugués | Inglés | Trigger |
|---|---|---|---|
Contains credential harvesting logic and Telegram bot integration for real-time exfiltration.
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING LURE │
│ - Email/SMS with fake Chase alert │
│ - Link to spoofed Chase login page │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. FAKE LOGIN PAGE LOADING │
│ - Victim lands on Chase-branded phishing site │
│ - Displays urgent security message │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL SUBMISSION │
│ - Victim enters Banking credentials │
│ - Form captures input without validation │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA EXFILTRATION │
│ - Stolen credentials sent to Telegram bot │
│ - Single token used for communication │
└──────────────────────────────────────────────────────────┘
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING LURE │
│ - Email/SMS with fake Chase alert │
│ - Link to spoofed Chase login page │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. FAKE LOGIN PAGE LOADING │
│ - Victim lands on Chase-branded phishing site │
│ - Displays urgent security message │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL SUBMISSION │
│ - Victim enters Banking credentials │
│ - Form captures input without validation │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA EXFILTRATION │
│ - Stolen credentials sent to Telegram bot │
│ - Single token used for communication │
└──────────────────────────────────────────────────────────┘
Pages with identical visual appearance (based on perceptual hash)