Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B752A364230C192D601747C4FFA5F779639EA396E31D501CE0AE22629783DD5ECB3AB8 |
|
CONTENT
ssdeep
|
96:R39GS27MrS2eSTuliZqj1ufcya/koXLk77mbukPVieu7mbp5Vi77mbAfViq7mbOc:FNbW8+iZqUUN7+ciMihiai8pFF6/5pHT |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8cccad3333332766 |
|
VISUAL
aHash
|
8018381800000081 |
|
VISUAL
dHash
|
13b0213101110013 |
|
VISUAL
wHash
|
813cff000cff00ff |
|
VISUAL
colorHash
|
38007000000 |
|
VISUAL
cropResistant
|
13b0213101110013 |
• Ameaça: Phishing/Impersonaçao
• Alvo: DogeUB (Proxy/Unblocker)
• Método: Spoofing de domínio através de subdomínios aleatórios
• Exfil: Captura de dados via JavaScript
• Indicadores: Ofuscação de JS malicioso detectada
• Risco: Alto devido ao potencial roubo de credenciais
The site uses obfuscated JS to intercept user input and browser data before forwarding it to external C2 servers.
The site acts as a proxy to monitor all unencrypted traffic from the user's browser.
Pages with identical visual appearance (based on perceptual hash)