Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CB23B8B358C42B2B51D342C593105A0BF3D18205E3BA9A5FE5EE831A27C6D4DCD6B76C |
|
CONTENT
ssdeep
|
768:7XdiE704BW9xkCDlM3ri7oaHqdifvbYmNDzFW6T4pZkfS4RGL4oy4QhEOK2Ji:7N+4BOxkKu8oYYsvbYmNDpWnpZkKYGOS |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
946be994a7eaa096 |
|
VISUAL
aHash
|
ff0000003e5e4e06 |
|
VISUAL
dHash
|
71f0c8ececacdc8e |
|
VISUAL
wHash
|
ff0000047e7e7e5e |
|
VISUAL
colorHash
|
02000000038 |
|
VISUAL
cropResistant
|
0001416363c90006,d495d35233173574,94c4f0a08a1e888e,9d614161372733b3,64682a643024270e,b6e0f0f8ddc79373,6d61656555d5a6a6,31d4d0ececbcdc8e |
• Ameaça: Phishing
• Alvo: Usuários interessados na Bitcore Surge ou criptomoedas
• Método: Imitação e coleta de dados baseada em formulários
• Exfil: Envio de formulários JavaScript provavelmente para um ponto final desconhecido.
• Indicadores: Incompatibilidade de domínio, formulário solicitando PII, ofuscação JavaScript.
• Risco: ALTO
The website uses a form to collect personal information from users, pretending to be a legitimate platform. This is a common tactic to obtain credentials and potentially other sensitive data. The form submissions are likely sent to a server controlled by the attacker.
After collecting the data the attacker can try to make more spear phishing attacks.
Pages with identical visual appearance (based on perceptual hash)