Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1514153318545C93B5693A6A49321DF2AB1D3C613CB0318A5B2F993ED9BD7D85CDD028C |
|
CONTENT
ssdeep
|
48:sHhHcpnifS6uM6hRx1fRYwiMucL+CDQyS:CaiS6uM6hIk+1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e6dc997174c43199 |
|
VISUAL
aHash
|
ffffe7c3c3c3e7e7 |
|
VISUAL
dHash
|
8c140c4d0e0e4c0c |
|
VISUAL
wHash
|
42c7c3c3c3c3e3c3 |
|
VISUAL
colorHash
|
07600006000 |
|
VISUAL
cropResistant
|
8c140c4d0e0e4c0c,100c32b2b2320c10,0929696577b4da5a |
• Amenaza: Kit de phishing para robo de credenciales.
• Objetivo: Usuarios de CMR Puntos.
• Método: Formulario de inicio de sesión falso para robar credenciales.
• Exfil: Punto de exfiltración de datos desconocido.
• Indicators: Dominio registrado recientemente, JavaScript ofuscado, formularios detectados.
• Risk: ALTO - El robo de credenciales es inminente.
The phishing kit captures RUT (Chilean national ID) and internet Banking password (Clave Internet) via a fake login form. Data is likely exfiltrated in real-time to an attacker-controlled server for immediate account takeover.
The kit includes functionality to intercept one-time passwords (OTPs) sent via SMS or authentication apps, enabling bypass of two-factor authentication for CMR Puntos accounts.
JavaScript file with potential for credential exfiltration or dynamic payload delivery.
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING EMAIL │
│ - Email mimics CMR Puntos branding │
│ - Contains link to fake login page │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM VISITS FAKE CMR PUNTOS SITE │
│ - Fake page replicates legitimate Banking portal │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL HARVESTING │
│ - Victim enters login credentials │
│ - Data captured via fake form │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA EXFILTRATION │
│ - Credentials sent via HTTP POST │
│ - Standard form submission to attacker server │
└──────────────────────────────────────────────────────────┘
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING EMAIL │
│ - Email mimics CMR Puntos branding │
│ - Contains link to fake login page │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM VISITS FAKE CMR PUNTOS SITE │
│ - Fake page replicates legitimate Banking portal │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL HARVESTING │
│ - Victim enters login credentials │
│ - Data captured via fake form │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA EXFILTRATION │
│ - Credentials sent via HTTP POST │
│ - Standard form submission to attacker server │
└──────────────────────────────────────────────────────────┘
Pages with identical visual appearance (based on perceptual hash)