Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B2A3EE234169752B4437C7C1306A5B3BE1A6998FFEFB0A405EDCC7FA2AF9C90741A119 |
|
CONTENT
ssdeep
|
1536:AJqtpR4nXBKpSpFl26vmGLZcQOWnWDYSSw8:9UM5GLZcQOWnWDYSSw8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93076d0353177f0d |
|
VISUAL
aHash
|
001f0f3e6f0f01c7 |
|
VISUAL
dHash
|
dcbf3cdcdcb8b30f |
|
VISUAL
wHash
|
000f0f3f7f0f01e7 |
|
VISUAL
colorHash
|
00003400400 |
|
VISUAL
cropResistant
|
fdb77cdcdcb9f30f,dcbd3cdcdcfcbb77,c6d60c981b1c495a,48d9a9676168cac8,6e878b85a7a7ae8d,68100c32320c21d4 |
โข Threat: Phishing
โข Target: Users of Neuroverde Prime AI (or potential users)
โข Method: Deception via a fake login form
โข Exfil: https://neuroverdeprimeai-today.com/assets/submit.php
โข Indicators: Domain age, obfuscation, form submissions
โข Risk: High
The attacker attempts to steal user credentials (name, email and phone number) via a fake form.
The attacker employs Javascript obfuscation to hide and potentially execute malicious code. This helps to evade detection.
Pages with identical visual appearance (based on perceptual hash)