Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T187C1E146280B670E7BF491098FBEB380E3A671F4D7204B5232B9081F43D8668DC778A7 |
|
CONTENT
ssdeep
|
96:MeAeyZovkDGPBfFBn24r00//Ghwhkd2xPACLIDwSLmqlK6i1yfJUAeSjurYEP5rI:MeAeyZovkDGpbn24r00//Ghwhkd2ZACK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
be61613e61613e69 |
|
VISUAL
aHash
|
00ffffffffbfffff |
|
VISUAL
dHash
|
2100000020280020 |
|
VISUAL
wHash
|
00f0fcfcf090f0f0 |
|
VISUAL
colorHash
|
07000038000 |
|
VISUAL
cropResistant
|
0000200028280020,0020033939032000 |
• Ameaça: Fraude de investimento/credenciais
• Alvo: Usuários financeiros
• Método: Exfiltração via JS
• Exfil: Backend desconhecido
• Indicadores: Código JS ofuscado
• Risco: Alto
Uses a fake login portal to capture user credentials for financial accounts.
Hides the exfiltration endpoint using string manipulation functions.