Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19A41632250195D2B13C2D0D0A7F0B60FA7938743C6074F0686F487CEAEC8DB8CD992E9 |
|
CONTENT
ssdeep
|
48:9y2Dg6G/QNHlZKNWomvqJvzj+GaDXIMpl:xGClbvqJbiDh |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b33333dccccc464c |
|
VISUAL
aHash
|
24e7e7ffffffffff |
|
VISUAL
dHash
|
084c0c0010080000 |
|
VISUAL
wHash
|
0004e0f83f3f0f0f |
|
VISUAL
colorHash
|
000000001c0 |
|
VISUAL
cropResistant
|
084c0c0010080000,0161457131414101 |
• Ameaça: Phishing
• Alvo: Usuários não especificados
• Método: Imitação e coleta de credenciais.
• Exfil: https://patrona.matesdaddy.com/santacruz.php
• Indicadores: Hospedagem gratuita, envio de formulário, ofuscação.
• Risco: Alto
The attacker attempts to steal user credentials by creating a fake login form on a free hosting service. Users are tricked into entering their login details, which are then sent to a server controlled by the attacker.
JavaScript code has been obfuscated to hide its true functionality and prevent easy analysis of the phishing attack.
Found 2 other scans for this domain