Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F9B184621518919B12534EC2FFA37B4D32EBF22EDDA21D54D2FE839C4ADBDC5C429812 |
|
CONTENT
ssdeep
|
96:non9C9uKs36I0UQXifzzaTDUTrT+2GuYsClRlKhzLo6ET:ys9fSQX0YuHBYsYoBEj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b2333e7b35c82394 |
|
VISUAL
aHash
|
0707070707070f0f |
|
VISUAL
dHash
|
2dadbdbdbcfdbd3c |
|
VISUAL
wHash
|
07070f0f0f0f1f1f |
|
VISUAL
colorHash
|
0b0002000c0 |
|
VISUAL
cropResistant
|
8e96968eb89696c0,9e9e9e96de9e9efe,acdecace6e6e4e2e |
• Ameaça: Potencial coleta de dados.
• Alvo: Usuários do Titan Trade.
• Método: Formulário de login.
• Exfil: Envio de dados ao servidor.
• Indicadores: O domínio contém o nome da marca.
• Risco: BAIXO - Página de login plausível. É necessário mais investigação do Titan Trade e do domínio para verificar a legitimidade.
The phishing page presents a fake login form for Titan Trade, capturing email and password inputs in real-time. Submitted credentials are likely exfiltrated to an attacker-controlled server for immediate use in account takeover attacks.
The kit includes modules for intercepting one-time passwords (OTPs) and credit card details. After capturing initial credentials, the page may dynamically request additional sensitive information under the guise of 'verification' or 'security checks'.
Large JavaScript file containing obfuscated credential harvesting and data exfiltration logic.
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING EMAIL │
│ - Email mimics Titan Trade branding │
│ - Contains link to fake login page │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM VISITS FAKE TITAN TRADE SITE │
│ - Page replicates legitimate Banking portal │
│ - Displays convincing login form │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL SUBMISSION │
│ - Victim enters Banking credentials │
│ - Form appears identical to real site │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. CREDENTIAL EXFILTRATION │
│ - Data sent via HTTP POST (standard form submission) │
│ - Transmitted to attacker-controlled server │
└──────────────────────────────────────────────────────────┘
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING EMAIL │
│ - Email mimics Titan Trade branding │
│ - Contains link to fake login page │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM VISITS FAKE TITAN TRADE SITE │
│ - Page replicates legitimate Banking portal │
│ - Displays convincing login form │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL SUBMISSION │
│ - Victim enters Banking credentials │
│ - Form appears identical to real site │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. CREDENTIAL EXFILTRATION │
│ - Data sent via HTTP POST (standard form submission) │
│ - Transmitted to attacker-controlled server │
└──────────────────────────────────────────────────────────┘
Pages with identical visual appearance (based on perceptual hash)