Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AEC2207C20EC15B7903B8CCAB824395DA871934BCF26C8976AAD53D63FD2811B550E7B |
|
CONTENT
ssdeep
|
384:DybgbzkDBuDBP8pYy5E2zu7TVBq9XqLTV5tDUTghoVupJVCzN:DybgbzT8pYytIqqLTV5tD+gqAGN |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9616bb391cb97911 |
|
VISUAL
aHash
|
0e060e1600ffffff |
|
VISUAL
dHash
|
6cecece46495080e |
|
VISUAL
wHash
|
0c06041404ffffff |
|
VISUAL
colorHash
|
16600000002 |
|
VISUAL
cropResistant
|
9f9b9f9fadedcfc6,9e0c000c0f370c4c,7c6cececf4646471 |
โข Threat: Potential brand abuse / unauthorized store.
โข Target: TikTok users.
โข Method: Possibly an unverified third-party TikTok shop.
โข Exfil: No data exfiltration is apparent.
โข Indicators: Unofficial domain, but no clear phishing signs.
โข Risk: LOW - Potential brand misrepresentation but no direct threat.
The phishing kit captures TikTok login credentials via a fake login portal. Submitted credentials are likely exfiltrated to an attacker-controlled server for immediate account takeover.
If multi-factor authentication (MFA) is enabled, the kit may prompt victims to enter OTP codes, which are intercepted and relayed to the attacker in real-time.
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. VICTIM RECEIVES PHISHING LURE โ
โ - Fake TikTok email/notification with malicious link โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. VICTIM VISITS FAKE TIKTOK PAGE โ
โ - Phishing site mimics legitimate TikTok login โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. CREDENTIAL INPUT โ
โ - Victim enters Banking/login credentials โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. DATA CAPTURE & EXFILTRATION โ
โ - Credentials sent via HTTP POST (form submission) โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. VICTIM RECEIVES PHISHING LURE โ
โ - Fake TikTok email/notification with malicious link โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. VICTIM VISITS FAKE TIKTOK PAGE โ
โ - Phishing site mimics legitimate TikTok login โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. CREDENTIAL INPUT โ
โ - Victim enters Banking/login credentials โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. DATA CAPTURE & EXFILTRATION โ
โ - Credentials sent via HTTP POST (form submission) โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Pages with identical visual appearance (based on perceptual hash)