Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18D6185F3C200CC1F1752C06449A1BD5A016681CBCA5C2E2262F892EF19DAEF4D9733B6 |
|
CONTENT
ssdeep
|
48:nbVpbfdspa3SJgBHor9iQoI2wCiPDTscPIaN5806Iq:nh3cJ+IGTIIaNy |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
912d7885f45a2eda |
|
VISUAL
aHash
|
434300007e7efcc3 |
|
VISUAL
dHash
|
969679968aaae98a |
|
VISUAL
wHash
|
43430000fffffcc3 |
|
VISUAL
colorHash
|
090000001c0 |
|
VISUAL
cropResistant
|
d4f4e9b3b4ed7301,3999d69696d6e626,96963269664eb9a9,9b153728287575b0,232ce2d296725a9a,58cac66e46c48566,9696326126a6a4a4,243454ac26d2ed6d,929293952664e452,2929a5b786965656,3a3ab533555525a4,cba333a0a0b136b8,969679968aaae98a |
• Ameaça: Phishing
• Alvo: Clientes do BRI
• Método: Falsificação através de domínio suspeito
• Exfil: Não claro, provavelmente dados ou credenciais
• Indicadores: Domínio incompatível, texto promocional, origem desconhecida
• Risco: Alto
The attacker is likely attempting to steal login credentials or other sensitive information by mimicking the appearance of BRI and offering an incentive to participate.
The attackers are using a promotion (prize) to trick the user into engaging with the site.
Pages with identical visual appearance (based on perceptual hash)