Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10A236497710816B9C3F3848944402990A2C7EB5FC9D19770C7780E7B2BE2A6267A5F7F |
|
CONTENT
ssdeep
|
768:8S3v1ygaHjS34Pt4PP4a/IesLdMuPZaPcGC72l0PsPLsAqY7/cz/:8S3v1PgjK41434a/IecMuPZaPcGC72lA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
becd1ec1c1699632 |
|
VISUAL
aHash
|
ff9783c1efff8187 |
|
VISUAL
dHash
|
23272f0b1b332f2d |
|
VISUAL
wHash
|
ff918181cbfb8183 |
|
VISUAL
colorHash
|
06201000180 |
|
VISUAL
cropResistant
|
23272f0b1b332f2d,393139193933313d,01112561484b0b82,000124dac82c0300,bcf9830d2d2b491f,00114e889cd42100,c4e4557993969687,48e936081866e0bc,004823e0cce41340 |
• Threat: Credential harvesting phishing kit
• Target: Stellantis customers
• Method: Fake financial service forms to steal sensitive information
• Exfil: Potential data exfiltration via obfuscated JavaScript
• Indicators: Newly registered domain, mismatched branding, financial forms
• Risk: HIGH - Immediate credential theft
Pages with identical visual appearance (based on perceptual hash)