Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A4B343214557243B22339F816BC5AB7D518B62D8A337CE07F6F44F2AAFC4E54A94C21E |
|
CONTENT
ssdeep
|
768:H3OHo2sj4P5gqyrm5Yqki96jL0xZoHP49JtA0C6:XOHovj4Po65YJiJxZoHPoC6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fc5c8b0135f848ee |
|
VISUAL
aHash
|
0080d0820200ff81 |
|
VISUAL
dHash
|
1b65243666e00f2b |
|
VISUAL
wHash
|
01b8f082b37eff81 |
|
VISUAL
colorHash
|
02000000006 |
|
VISUAL
cropResistant
|
1849c9342999b136,ae8eaea2b2ae8ea6,9749858189c1c5c7,aa314d4d31452b2b,036b64343626e4aa,2b2b2b3b4c544e4b |
• Ameaça: Phishing
• Alvo: Clientes Bradesco Empresas
• Método: Imitação e coleta de dados
• Exfil: Desconhecido (devido à ofuscação)
• Indicadores: Incompatibilidade de domínio, código ofuscado e formulários
• Risco: Alto
The site mimics the look and feel of the Bradesco Empresas website to trick users into entering their login credentials. The form data is likely sent to a server controlled by the attackers.
Obfuscated Javascript could be used for advanced keylogging, or redirecting to another phishing site.
Pages with identical visual appearance (based on perceptual hash)