Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DDC264309089ED3B0493B2D1F2691B67B7959304CB1B871963FCC7A92FD6E09DC3A5A1 |
|
CONTENT
ssdeep
|
384:8DJutCl+ut9c1ZCW9NqmY0fbGAEzTX/WgtG:8DJud9NGOdEzTPTtG |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
da34e9eb145a9469 |
|
VISUAL
aHash
|
0000060606fff9ff |
|
VISUAL
dHash
|
de8c9cac9c233323 |
|
VISUAL
wHash
|
000006060fffffff |
|
VISUAL
colorHash
|
1b002000180 |
|
VISUAL
cropResistant
|
a0808030308080a0,a280c034349080b2,a080a0b434b080a2,9200b8badaf80042,400be0cccce82388,9b00333b2b630323,da3ecc9c9cacac98,317978b93c3c7a7e |
The phishing kit targets Banking users by presenting a fake login portal that captures credentials in real-time. The 'OTP Stealer' component intercepts one-time passwords (OTPs) via form submission or simulated authentication flows, enabling immediate account takeover.
Post-credential capture, the kit may initiate session hijacking by injecting malicious scripts into the victim's browser or redirecting to a fake 2FA verification page to maintain access.
Highly obfuscated JavaScript file likely containing credential harvesting and OTP interception logic.
Here's a generic ASCII art attack flow diagram for the phishing attack:
```
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING LINK │
│ - Email/SMS directs to fake Blackrose Finbitnex page │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. FAKE LOGIN PAGE DISPLAYED │
│ - Mimics legitimate Banking portal │
│ - Requests credentials and OTP │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIALS AND OTP CAPTURED │
│ - User inputs sensitive information │
│ - Form collects all entered data │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA EXFILTRATION │
│ - Harvested data sent via HTTP POST │
│ - Standard form submission to attacker server │
└──────────────────────────────────────────────────────────┘
```
Here's a generic ASCII art attack flow diagram for the phishing attack:
```
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING LINK │
│ - Email/SMS directs to fake Blackrose Finbitnex page │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. FAKE LOGIN PAGE DISPLAYED │
│ - Mimics legitimate Banking portal │
│ - Requests credentials and OTP │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIALS AND OTP CAPTURED │
│ - User inputs sensitive information │
│ - Form collects all entered data │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA EXFILTRATION │
│ - Harvested data sent via HTTP POST │
│ - Standard form submission to attacker server │
└──────────────────────────────────────────────────────────┘
```
Found 1 other scan for this domain