Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AD91EF1822853B4F999852A3C3752E94D3E1941EC7724D58A81EE72F1C8814EEC7F9FC |
|
CONTENT
ssdeep
|
96:A3ydpoIL/N+lglAtyHL5ZiNr2t5CLJWfsT3yDSxyHJHAPboRbDY7YoDSZQ:j2kcRMgc0v |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b29e9a3131dccc99 |
|
VISUAL
aHash
|
dfe7bdc3c3ffefff |
|
VISUAL
dHash
|
394c68049e600800 |
|
VISUAL
wHash
|
1c243c3cc0d0fcfc |
|
VISUAL
colorHash
|
07018000600 |
|
VISUAL
cropResistant
|
394c68049e600800 |
• Ameaça: Phishing
• Alvo: Usuários do Plala
• Método: Imitação da página de login.
• Exfil: cgi-binsso/pf/agent_sso.php
• Indicadores: Incompatibilidade de domínio, javascript ofuscado, ação de formulário para script PHP suspeito
• Risco: Alto
The attacker is attempting to steal user credentials by mimicking the Plala login page and redirecting the submitted information to a malicious server.
The javascript code on the page is obfuscated in an attempt to hide the malicious logic.
1. Step 1: Script loads and initializes fingerprinting components (td_3j) 2. Step 2: Collects browser/OS fingerprint via tmx_run_page_fingerprinting() 3. Step 3: Monitors form submissions and session data via td_1B() 4. Step 4: Encodes collected data using XOR obfuscation (td_5I) 5. Step 5: Creates hidden iframe for exfiltration (td_5o) 6. Step 6: Sends data via tmx_post_session_params_fixed() to attacker server 7. Step 7: Uses CSP nonce bypass to inject additional malicious scripts
1. Step 1: Script loads and initializes fingerprinting components (td_3j) 2. Step 2: Collects browser/OS fingerprint via tmx_run_page_fingerprinting() 3. Step 3: Monitors form submissions and session data via td_1B() 4. Step 4: Encodes collected data using XOR obfuscation (td_5I) 5. Step 5: Creates hidden iframe for exfiltration (td_5o) 6. Step 6: Sends data via tmx_post_session_params_fixed() to attacker server 7. Step 7: Uses CSP nonce bypass to inject additional malicious scripts
common.jstmx_post_session_params_fixed()tmx_run_page_fingerprinting()td_1B() - form data collectiontd_5o() - iframe content accesstd_3j() - initialization triggerPages with identical visual appearance (based on perceptual hash)
Found 3 other scans for this domain