Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15D52E97101006E3F82C586D8E2B9770B3682C2D7C6464784D3F5879FADD9DE2DC2AA9D |
|
CONTENT
ssdeep
|
192:LFqGYXIjJFLJHAlm121lBVxlWxab1Wgl48qlBbtaH/G6os+NJHAlm125lBV/lWxj:LFnSWmRRx91bqm9R/91Vy |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ece4339966329933 |
|
VISUAL
aHash
|
ffdbc3d352180000 |
|
VISUAL
dHash
|
96969696b6b21212 |
|
VISUAL
wHash
|
ffdbdbd3d3180000 |
|
VISUAL
colorHash
|
38000000e00 |
|
VISUAL
cropResistant
|
96969696b6b21212 |
• Ameaça: Phishing
• Alvo: Usuários do Spotify
• Método: Imitação via uma página de login falsa.
• Exfil: login.php (com base nas ações do formulário)
• Indicadores: Domínio não relacionado, formulário presente, código ofuscado.
• Risco: ALTO
The attackers are using a fake Spotify login page hosted on a different domain (eat-co.com) to steal user credentials. Users are tricked into entering their login information, which is then sent to the attackers.