Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T152E3F874E3F5E1F9E106D3E0E5727835369619B9AF01CA4843F98FE8CAA245D895CC83 |
|
CONTENT
ssdeep
|
1536:2Cjo44u44ynOI4DquYW0oxNO96BIn3DmeXYW0ox6O96BIn3DXeoYW0oxDO96BInd:g4DDeoeNeLp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9606e9499bce96c6 |
|
VISUAL
aHash
|
7f0004040400ffff |
|
VISUAL
dHash
|
e08ccceccccca330 |
|
VISUAL
wHash
|
ff0036060600ffff |
|
VISUAL
colorHash
|
02006000000 |
|
VISUAL
cropResistant
|
a2a1859999858180,60e8e8a424666b02,2998dcec4d6c6460,0000000030381e1e,ec8ccceccccccc34 |
• Ameaça: Phishing Financeiro / Coleta de credenciais
• Alvo: Clientes do Corevest
• Método: Impersonação de empresa de gestão de ativos
• Exfil: Envio de formulário via JavaScript
• Indicadores: Código ofuscado, número de telefone genérico
• Risco: Alto - roubo de credenciais e dados pessoais
The site uses a fake banking interface to capture user credentials for 'E-Banking' access, which are then exfiltrated via obfuscated JS requests.
Leverages the aesthetic of a financial institution to build false trust with victims.