Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1851102700C3D565347A181E6F9A77E072A40C786D35A0F5095B4D3FD1ACDB09C9EF560 |
|
CONTENT
ssdeep
|
24:kHks1wspc8MT0C7OkCQqb5SpXQEiKn0SZxZjRV8x0JWM:C1zpxk4b5SpMY0c/jRKWJf |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b8cc9b7623336638 |
|
VISUAL
aHash
|
ffffdbc3c3c3c3c3 |
|
VISUAL
dHash
|
b0b2b28e96969696 |
|
VISUAL
wHash
|
7e5b5943c0c3c3c3 |
|
VISUAL
colorHash
|
07c00000000 |
|
VISUAL
cropResistant
|
a2948e80aa8ee0b2,b0b2b28e96969696 |
• Threat: Account Suspension Scam
• Target: Facebook Users
• Method: Impersonation through a suspension notification.
• Exfil: Unknown (Likely credential harvesting)
• Indicators: Domain mismatch, suspension message.
• Risk: High
The attacker aims to steal user credentials by mimicking a Facebook notification. The user is prompted to click a link or provide information believing it is to regain access to their account. The javascript obfuscation detected would likely be to make it hard to spot the malicious action.
The attack may lead to the download and execution of malware.
Pages with identical visual appearance (based on perceptual hash)