Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C722A632B1589C2F5583C3E5ABF1A62F72EDD350CF0286A685D4DB184FCBD94C9B2491 |
|
CONTENT
ssdeep
|
192:KvZP7YM439Pe4uykvlj1jLBI00zrzMl6KR0zrzMC:oZPTkhLuykvlj132nMl6KyMC |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b3cc6633992399cc |
|
VISUAL
aHash
|
fffffffbdbe7a5db |
|
VISUAL
dHash
|
302a323232084d30 |
|
VISUAL
wHash
|
f8f8d8d83b3b0303 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
302a323232084d30 |
• Threat: Data harvesting phishing targeting Bunq customers.
• Target: Bunq customers.
• Method: Fake Bunq form stealing personal and financial information.
• Exfil: Data sent to config/telegram.php
• Indicators: Domain mismatch, Form asks for personal and financial information
• Risk: HIGH - Immediate risk of identity and financial theft
Pages with identical visual appearance (based on perceptual hash)
Found 3 other scans for this domain