Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FD44C2785918AC2E0641848DE1CF3798B15FC24A8B0247ABB36B2D7F87E14B7757C663 |
|
CONTENT
ssdeep
|
1536:r3OOtc2B1U1g14yHJ4BHp2c3or502X2y2/HiHplFXWXHiuH31VxUgoC1wIUF:r3BOAGVup8c |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f08ad28b74a9de70 |
|
VISUAL
aHash
|
ffe7c3c3c3ffc2c0 |
|
VISUAL
dHash
|
59482a9696695c54 |
|
VISUAL
wHash
|
ff204343c3ffc0c0 |
|
VISUAL
colorHash
|
01007000000 |
|
VISUAL
cropResistant
|
59482a9696695c54,69e48d6b8b8ad232,0555a9a93763b9ac,44946c69b2967175,12326226995bc9c9,d9999ae56515d5d5,3979f8a8ade9a3b1,33ccac4cce9c8c63 |
• Amenaza: Phishing
• Objetivo: Usuarios de PayPal
• Método: Redirección de URL e ingeniería social
• Exfil: La ofuscación de JavaScript puede indicar exfiltración de datos. La URL final después de la redirección es desconocida, por lo que la ubicación también es desconocida.
• Indicadores: Acortador de URL, suplantación, ofuscación de javascript, envío de formularios javascript.
• Riesgo: ALTO
The attacker aims to steal user credentials by redirecting them to a fake login page that mimics PayPal's legitimate site. Javascript obfuscation and form submission detection suggest the use of javascript to harvest and send the user's data to a malicious server.
The use of rebrand.ly is a method of hiding the malicious destination. The redirect is a form of social engineering.
mktconf.jsPages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain