Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1452365F390A4D077078EF6E0B566671FB7C3878BD9460FE29AE847185E86DC18E1341A |
|
CONTENT
ssdeep
|
768:I1gMkvdq3FGMq6COFXQdC3gf6IgMkvdq3FGMq6COd2/RPdXsiK08c2705C81O7pN:I1gMkvdq3FGMq6COFXQdC3gfNgMkvdqt |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
853e6f634f1411dc |
|
VISUAL
aHash
|
00005e7e7e6e7e7e |
|
VISUAL
dHash
|
41ecb4b2d2cac6f2 |
|
VISUAL
wHash
|
00005e5e7e6e7e7a |
|
VISUAL
colorHash
|
0e007000000 |
|
VISUAL
cropResistant
|
3222b2b2dacad2d2,41ecb4b2d2cac6f2,4153666749491939,89c9390f23636663 |
โข Threat: Phishing
โข Target: Steam users
โข Method: Impersonation with malicious forms
โข Exfil: Potentially user credentials
โข Indicators: Suspicious domain, obfuscated Javascript, form submission.
โข Risk: HIGH
The attacker is likely using a fake login form to steal the victim's Steam credentials. The obfuscated Javascript and forms on the page are indicators of this.
prototype-1.7.js?v=npJElBnrEO6W&l=english&_cdn=akamaiPages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain