Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FD44C2785918AC2E0641848DE1CF3798B15FC24A8B0247ABB36B2D7F87E14B7757C663 |
|
CONTENT
ssdeep
|
1536:r3OOtc2B1U1g14yHJ4BHp2c3or502X2y2/HiHplFXWXHiuH31VxUgoC1wIUF:r3BOAGVup8c |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f08ad28b74a9de70 |
|
VISUAL
aHash
|
ffe7c3c3c3ffc2c0 |
|
VISUAL
dHash
|
59482a9696695c54 |
|
VISUAL
wHash
|
ff204343c3ffc0c0 |
|
VISUAL
colorHash
|
01007000000 |
|
VISUAL
cropResistant
|
59482a9696695c54,69e48d6b8b8ad232,0555a9a93763b9ac,44946c69b2967175,12326226995bc9c9,d9999ae56515d5d5,3979f8a8ade9a3b1,33ccac4cce9c8c63 |
• Ameaça: Phishing
• Alvo: Usuários do PayPal
• Método: Redirecionamento de URL e engenharia social
• Exfil: A ofuscação de JavaScript pode indicar exfiltração de dados. A URL final após o redirecionamento é desconhecida, portanto, a localização também é desconhecida.
• Indicadores: Encurtador de URL, personificação, ofuscação de javascript, envio de formulários javascript.
• Risco: ALTO
The attacker aims to steal user credentials by redirecting them to a fake login page that mimics PayPal's legitimate site. Javascript obfuscation and form submission detection suggest the use of javascript to harvest and send the user's data to a malicious server.
The use of rebrand.ly is a method of hiding the malicious destination. The redirect is a form of social engineering.
mktconf.jsPages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain