Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T150A21B617904DE6600DB89D99633127A62F88351E943068CF9B9C7F843AFCBDCB37981 |
|
CONTENT
ssdeep
|
384:rJtlN7De8BXPvFZqbiMxze7ymsBCgWCs1HsBCgWCtXZee:rJtlNuOdZqbiMxzeGmiCgb6iCgbtXce |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d561b03d8a3bd83a |
|
VISUAL
aHash
|
f272603c381a06ff |
|
VISUAL
dHash
|
82c688e870747c30 |
|
VISUAL
wHash
|
f272603c381c0eff |
|
VISUAL
colorHash
|
0e006000040 |
|
VISUAL
cropResistant
|
b000200000000000,a2c688e860746c30 |
• Amenaza: Phishing
• Objetivo: Credenciales financieras/PII
• Método: Suplantación de una institución bancaria falsa
• Exfil: Datos del usuario enviados a través de formularios web
• Indicadores: Estética bancaria genérica, sin información regulatoria
• Riesgo: Alto
The site mimics a legitimate banking portal to entice users to enter PII during an 'account opening' or 'login' process.
Collecting PII for use in wider financial fraud or identity theft operations.