Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A50395729161EA7381C3C7F0933A676AB3C1C15ADB634B4982FC634D6BD2C52DC3661A |
|
CONTENT
ssdeep
|
768:Lili35IwuSI4I1q/bmuENs10YuT1wBGtu9/7ImC47:ui35IoI4I1q/b4Ns10h1wBGu/7IZ47 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9210ed7ee1659758 |
|
VISUAL
aHash
|
00040e0e0c0c00ff |
|
VISUAL
dHash
|
839998dc9818c60c |
|
VISUAL
wHash
|
004f6e6ece8e00ff |
|
VISUAL
colorHash
|
39400040002 |
|
VISUAL
cropResistant
|
e9696f65d232f8f0,0400000000000000,838998dc98980c84 |
• Threat: E-commerce platform mimicking TikTok's interface for potential scams or data harvesting.
• Target: TikTok users interested in shopping.
• Method: Replicates TikTok's live shopping experience to trick users into making purchases on an untrusted platform.
• Exfil: JavaScript detected that may submit forms.
• Indicators: Domain tkmall98.vip does not match TikTok domain tiktok.com. The creation date of the domain is relatively new (220 days). Obfuscated JavaScript code is also present, suggesting malicious intent.
• Risk: HIGH - Potential financial theft and data exposure from an illegitimate e-commerce platform.
Pages with identical visual appearance (based on perceptual hash)