Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1907209F20500E9BA46078AF9DBE1FB58216FD14EDA1B0500A7FE87E513C7DE2ED29059 |
|
CONTENT
ssdeep
|
192:NWU+7WfV9PDJ7tn6WXk9OMuMZ0qhGgqhkOqhLJ7t5j+v+CyJ6umDa8wzXTOlnTa0:NWU+7WzPDqW86CzQPil9GyJWW8wHOln3 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b33c8dc7cc3330cc |
|
VISUAL
aHash
|
1f1f07c7cf072f0f |
|
VISUAL
dHash
|
febc9d88ac8acafc |
|
VISUAL
wHash
|
0f1f0707cf070f0f |
|
VISUAL
colorHash
|
07000000006 |
|
VISUAL
cropResistant
|
febc9d88ac8acafc,50888a8a8a8a8a8a,45012b13960e4d6d |
โข Threat: Credential Phishing
โข Target: Unsuspecting users
โข Method: Malicious webpage imitating file download
โข Exfil: Unknown, likely to steal credentials
โข Indicators: Unrelated domain, request for login details.
โข Risk: High
The site is designed to collect user credentials by presenting a login form for a download service, likely to steal the login credentials.
The use of javascript obfuscation techniques, makes it difficult to detect malicious activities.
| ID | Portuguese | English | Trigger |
|---|---|---|---|
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain