Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EC7418BFA72802B9E105C7DCC952A035316E24FE3B6186E4F7198F36B118CDD9869D93 |
|
CONTENT
ssdeep
|
1536:PfF+6yc9BoUpQ5rTADK7awVJA4E11gXqFM3UBWXc9BoUpQ5AWtGPOWIbZtieY579:Pec9HQqeVJA4E118c9HQwPyOV8cE6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
939939e6a66c6c85 |
|
VISUAL
aHash
|
162c3c043e3c2c3c |
|
VISUAL
dHash
|
e4d9d0c4e4c4d8dc |
|
VISUAL
wHash
|
163c7c347e3c2c3c |
|
VISUAL
colorHash
|
30003600000 |
|
VISUAL
cropResistant
|
e4d9d0c4e4c4d8dc |
• Ameaça: Phishing
• Alvo: Usuários de criptomoedas
• Método: Personificação e Engenharia Social
• Exfil: wss://gambler-work.com/api/ws
• Indicadores: Domínio recente, JS ofuscado, Apoio de celebridades, Oferta de criptomoedas.
• Risco: Alto
The site tries to look legitimate through the use of imagery and celebrity endorsements, and claims it is a crypto casino. The ultimate goal is to get the user to input personal information or provide crypto
Javascript obfuscation hides malicious functionality. The site likely aims to steal data from a potential victim's browser.
User fills <input name='username'> → submitForm() → fetch('https://failax.com/api/submit_credentials') → credentials sent to remote server
User fills <input name='username'> → submitForm() → fetch('https://failax.com/api/submit_credentials') → credentials sent to remote server
main-app-fef4a8898ec7782a.jssubmitForm()Pages with identical visual appearance (based on perceptual hash)