Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14B43D0A06B1E64BB0357A5D40BCD8F39E0A86349EE894B9145F84DF3D2C1CB2F8B7954 |
|
CONTENT
ssdeep
|
384:nGiBhkiHBbbS96t3Akibztv/cLYOpA2kihksC+/kzkgBeI4EbkLE7XH0bFmxGxkH:GHiJViLiaMg6O7lxze7mWdtW6Wky |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f73b1d4cc46c4562 |
|
VISUAL
aHash
|
0007e4fbffff0dfe |
|
VISUAL
dHash
|
74784a4080840902 |
|
VISUAL
wHash
|
0007ecfcfdff0302 |
|
VISUAL
colorHash
|
07000018006 |
|
VISUAL
cropResistant
|
747a484080840902,3434b03474744448,639898c998d8d825 |
• Ameaça: Phishing de credenciais
• Alvo: Clientes Bradesco
• Método: Imitação da página de login do Bradesco para roubar credenciais.
• Exfil: Ofuscação detectada sugere que os dados estão sendo enviados para outro lugar.
• Indicadores: Incompatibilidade de domínio, formulário presente, ofuscação detectada.
• Risco: Alto
The attacker sets up a fake website designed to look like the Bradesco login page. When a user enters their credentials, the site captures the username and password and sends it to the attacker.
Pages with identical visual appearance (based on perceptual hash)
Found 5 other scans for this domain