Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14B4565E16620A3AD90C7DAEDDF39DE90530F40BAB9B6D6C14ABEC75C9447D80FB06814 |
|
CONTENT
ssdeep
|
3072:fxiVgGQsl65JjRt3myWZJldkP77dWANo1JznfngguHSrqKHa5geEUH2Z1LC/Jw9p:fqqnzDZaU2P+w9L |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9f486336349e4fc1 |
|
VISUAL
aHash
|
00183c3c3c3c1c00 |
|
VISUAL
dHash
|
4c79713171697987 |
|
VISUAL
wHash
|
0018ffbd3d3dbd00 |
|
VISUAL
colorHash
|
0e000038000 |
|
VISUAL
cropResistant
|
f8dcaca38e5d5588,4c79713171697987,3434b5d4d4353434 |
โข Threat: None detected
โข Target: Mediapart users
โข Method: Legitimate website with cookie consent
โข Exfil: None
โข Indicators: Legitimate domain, brand name matches domain
โข Risk: LOW - No phishing detected
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 58 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 9 other scans for this domain