Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B8E229B4A230D335B1C247E8DA6425687A5FE1DCD7C695B4F388AF11B0D6CE8D5260CB |
|
CONTENT
ssdeep
|
384:4rAneu0TPRhiXkdvNTDhPhLxeAxeDWNW1Tp34PxeeJEmuW3AskoRWeMd:4rAneuahhPhleMeDGCSPxeeWmHBW |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d1633ebc681f1c68 |
|
VISUAL
aHash
|
806660f0f8de8e00 |
|
VISUAL
dHash
|
5cdcdad391346c31 |
|
VISUAL
wHash
|
806626f0f8debf90 |
|
VISUAL
colorHash
|
38018000600 |
|
VISUAL
cropResistant
|
d0f066a63936e0f2,f8b2b4c192c6c5ce,00100c4c4c0c1008,5cdcdad391346c31 |
• Ameaça: Roubo de credenciais
• Alvo: Usuários desavisados
• Método: Engano através de um formulário de registro falso.
• Exfil: wss://gambler-work.com/api/ws (URL WebSocket)
• Indicadores: Formulário de registro, imagem de celebridade, alegação de recompensa gratuita, javascript ofuscado.
• Risco: ALTO
The site utilizes a registration form to collect user email addresses and passwords, with the likely intent of stealing those credentials and gaining access to user accounts.
The site uses visual elements (celebrity endorsement) and incentives like 'free reward' to encourage users to enter their credentials. This aims to bypass user's security awareness
fbevents.jsPages with identical visual appearance (based on perceptual hash)