Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T174D3C7F2508066B782C793D9E72AB778F3D3404BDE690A55D2E1529AA5C2FE2CDC1B04 |
|
CONTENT
ssdeep
|
1536:e38W4R3n6EpEq3TRhEsOxwFVKXrcHvkIg:S8p6alkd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
921a51f5ad2b6971 |
|
VISUAL
aHash
|
0000003fffffffff |
|
VISUAL
dHash
|
d47cf9710c8f0e16 |
|
VISUAL
wHash
|
00000001efffffff |
|
VISUAL
colorHash
|
06000000180 |
|
VISUAL
cropResistant
|
7c5c71670e0f0e16,6368b5b26c66b9d9,d9f87c5c787cf16b |
• Ameaça: Phishing
• Alvo: Clientes BCP
• Método: Personificação através de um site semelhante.
• Exfil: Provavelmente rouba as credenciais inseridas nos formulários.
• Indicadores: Incompatibilidade de domínio, ofuscação, envios de formulários.
• Risco: Alto
The site uses a look-alike design of BCP to deceive users into entering their credentials into the form. These credentials are then stolen by the attackers.
The JavaScript code is obfuscated to make it difficult to analyze the actual malicious intent of the site and any potential data exfiltration.
node.jsPages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain