Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T199837632D393151390A7D1D8B1724B0933928B89C7134BB577FD67BAF9CECB52622298 |
|
CONTENT
ssdeep
|
1536:YVjIZagC8CQGee8XeSXehYPUgOq61eUdpgJOeUkeeIdqtS0QCQrCcSzQM/3uwfHY:RT1PPUgOq6QAqtWRcRk222I2222222NU |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b3cc4e393093cdcc |
|
VISUAL
aHash
|
7c307e4e4c4c4e44 |
|
VISUAL
dHash
|
c0e3e0988a9a8888 |
|
VISUAL
wHash
|
7c707e4e4e4e4646 |
|
VISUAL
colorHash
|
02200038000 |
|
VISUAL
cropResistant
|
c0e3e0988a9a8888,099924f031272b2b,d7693248cccc442c,272b6f37477b3b23,93d6692371f1e1e0 |
• Ameaça: Phishing
• Alvo: Usuários do Shopee
• Método: Imitação de um evento de brindes
• Exfil: Desconhecido (devido à ofuscação)
• Indicadores: Incompatibilidade de domínio, ofuscação, marca Shopee.
• Risco: ALTO
The attackers are likely trying to steal user credentials (username, password). They may use a form to collect this information and redirect the user to a legitimate site after.
The obfuscated Javascript has the potential to download and execute malware on a victim's machine. This is difficult to confirm without further analysis.
Pages with identical visual appearance (based on perceptual hash)