Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16C61417060662526574B0EF976B27F0D35ABC20ECA07341476BCA3D04BF7DB4EC19669 |
|
CONTENT
ssdeep
|
48:nq1uwelGJ3he4Dh/ewhe66oS4jQ8YUUHTx3f04smPKZWzdUkiX8jt4ta:nqZelGze4N2v6lS4E8YUUkwcgSa |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8d9e66c13c9933cc |
|
VISUAL
aHash
|
3c3e1e1e18783830 |
|
VISUAL
dHash
|
f0ec3032b2d1f267 |
|
VISUAL
wHash
|
3e3e1f1e1a787830 |
|
VISUAL
colorHash
|
1be00000000 |
|
VISUAL
cropResistant
|
c0b88ef1e3f2f3c1,1a98cacefcfcf871,f0ec3032b2d1f267,60705c2e0b051119 |
• Threat: Phishing
• Target: FORTIX Consulting users
• Method: Impersonation via login form on a suspicious domain
• Exfil: /landingpages/34ff6f31-91ae-43a9-a829-c34c8f2de6eb/wby4grg9i90uzzdz8d-ydpc-xxffrcjdqj8kpcl5lfq
• Indicators: Suspicious domain, unusual form action, JavaScript form submission.
• Risk: High
The attacker sets up a fake login page that mimics the appearance of FORTIX Consulting's login page. When a user enters their credentials, the information is sent to the attacker.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain