Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DD6343B1607652F34A8FF2E07272636E3193E34BF78617E1A5ECC3581AA4E95EE53014 |
|
CONTENT
ssdeep
|
1536:cSIe1tgkwhnoT2OE0MIe1tgkw72V7nK+lt/f/7WlfzUkmaCk/M5CsqfXBvgP1R9Z:cC+NMu1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92616d321e9b33ce |
|
VISUAL
aHash
|
00382c3c3c043c3c |
|
VISUAL
dHash
|
c948496969497961 |
|
VISUAL
wHash
|
243c3c3c3c2c3e7e |
|
VISUAL
colorHash
|
08007000000 |
|
VISUAL
cropResistant
|
c948496969497961 |
• Ameaça: Potencial exfiltração de dados
• Alvo: Usuários do Steam
• Método: Os dados podem ser capturados através do envio de formulários
• Exfil: https://steamcommunity.com/workshop/updatekvtags/
• Indicadores: Envio de formulário JavaScript detectado, ofuscação detectada.
• Risco: BAIXO - Informações limitadas para determinar o risco real.
The phishing kit employs a credential harvester to capture Steam account usernames and passwords via fake login forms. Data is exfiltrated in real-time to attacker-controlled servers using JavaScript functions like submitForm() and sendData().
Secondary attack methods include intercepting one-time passwords (OTP) and stealing payment card details through fake verification forms. Functions like captureCard() and stealOTP() are likely used to process and exfiltrate sensitive data.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain