Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FC84C7A3136832359033D3E9207A5736F6866DDFF6520D00CFDC9FE652DAC68295A4CA |
|
CONTENT
ssdeep
|
1536:2YLOxwOJUHWJzvhdPNt+x/7Giv5baxqWI8xDLdwDQBt7dDC4myR0vEnaGY/Cp1Qf:FSvqk0kxqWVaewyi/6QWIRBPHsF3Y |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bcc349c33e8ac93a |
|
VISUAL
aHash
|
ffe7ff8787ff8181 |
|
VISUAL
dHash
|
c88c832f2f833b33 |
|
VISUAL
wHash
|
3c42ff8787f98181 |
• Threat: Investment scam phishing kit targeting Russian citizens.
• Target: People in Russia interested in investing in Gazprom.
• Method: Fake website with a form to collect personal data, promising profits from gas trading.
• Exfil: Data likely sent to a server controlled by the attackers.
• Indicators: Free hosting, brand impersonation, claims of easy profits, request for personal information.
• Risk: HIGH - Potential for identity theft and financial loss.
Pages with identical visual appearance (based on perceptual hash)