Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18A441AF4935853F496874BD4F9711A0633A610EFFB92468883B48AE0FBE2ED9D435C61 |
|
CONTENT
ssdeep
|
3072:oyDeTa7jDw/4Q1pSBn1pSBy1pSB61pSBo1pSBafoi2cluAkYc1DI:Xp7jDw/47g7/to |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ce6131cece61cf30 |
|
VISUAL
aHash
|
00003c3c3c3c0000 |
|
VISUAL
dHash
|
8c3b69696969790c |
|
VISUAL
wHash
|
6289fd7d7d3c0c04 |
|
VISUAL
colorHash
|
31001000c00 |
|
VISUAL
cropResistant
|
8e8999e686a68799,8c3b69696969790c |
• Ameaça: Falsificação de identidade
• Alvo: Usuários do bet365
• Método: Site malicioso promovendo-se como um site oficial.
• Exfil: wss://tp-woekdksdiu-md-wdielskdks-socket.abcsport2.com
• Indicadores: Idade do domínio, ofuscação, envio de formulário JavaScript, redirecionamentos de URL
• Risco: Alto
The site is designed to trick users into entering their bet365 login credentials, which are then harvested by the attackers. It is likely the user will be redirected to an official site.
The site may be designed to inject and install malware or display malicious ads to the user.
User fills credentials in form → initGeetest4() → loadScript('https://www.z25r.xyz/config/initGeetest4.js') → fetch(exfiltration_target)
User fills credentials in form → initGeetest4() → loadScript('https://www.z25r.xyz/config/initGeetest4.js') → fetch(exfiltration_target)
config/initGeetest4.jsloadScript()jsonp()Pages with identical visual appearance (based on perceptual hash)