Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C6213016D7899C0CF1B7E0C8ADF0CB4E27618A46C306076892D073B9A18D5B198B6099 |
|
CONTENT
ssdeep
|
24:n/YrdIvv3AnsYPRNM0d9D55NyYyvD7wYKZwou+FgkNS:nSav6v55Nf8Is7+xS |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e666999933668ccc |
|
VISUAL
aHash
|
e7e7ffa5e7ffffff |
|
VISUAL
dHash
|
0828224c4c300000 |
|
VISUAL
wHash
|
e4f4f8e0243c3030 |
|
VISUAL
colorHash
|
07000007080 |
|
VISUAL
cropResistant
|
0828224c4c300000 |
• Threat: Phishing attack impersonating AG platform.
• Target: Users of AG platform, potentially in Asia.
• Method: Displaying a fake security check to redirect users to a malicious site.
• Exfil: Unknown, potentially redirects to a site that steals credentials or installs malware.
• Indicators: Domain mismatch, obfuscated JavaScript, suspicious domain name.
• Risk: HIGH - Potential for credential theft or malware infection.
Pages with identical visual appearance (based on perceptual hash)
Found 3 other scans for this domain