Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T110B342214557343722339F816AC4AB7D518B62D8A737CE07F6F44F2AAFC4E85A94C21E |
|
CONTENT
ssdeep
|
768:POKZi4xAhMlQDXookMki96jL0xZoHPfBEYzItxRx6:POKi4xUDXookriJxZoHPfqYzItZ6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9964031b6f2b75ca |
|
VISUAL
aHash
|
00c0e2c09c0e1d3d |
|
VISUAL
dHash
|
d90c26063958d9c1 |
|
VISUAL
wHash
|
00e6f2e29c1f1d3b |
|
VISUAL
colorHash
|
0b400040002 |
|
VISUAL
cropResistant
|
f7eef9b0e1c22c7b,a5e6a0a3a7e3a1a1,3ed2989810154e4e,2fb46474ce87e666,313939585819d9c3,d9cd2606313859d1,33f3a3a1c3672758,d3d3c332ccd4d4d8 |
• Ameaça: Phishing
• Alvo: Clientes Bradesco
• Método: Imitação através de um site parecido.
• Exfil: Obfuscação detectada sugere exfiltração de dados.
• Indicadores: Incompatibilidade de domínio, uso de ofuscação.
• Risco: Alto
The attacker likely aims to steal user credentials by creating a fake login form that redirects users to the real Bradesco login after credentials are submitted.
The presence of obfuscated Javascript suggests a possible malware payload, such as a keylogger or information stealer, that gets injected.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain