Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FB13C97104C47F6F52D382C593106A0BE3D78144E2B6995AF1EB831BA7C5E46CC2BB9D |
|
CONTENT
ssdeep
|
768:qY49K8tPxDB5clporTMFEhmy9BYzU3O/l6VskbGr8LpjtG5y3FsQEJUx:qYp8tPxDB5NrAFEhmymU3O/c+/rQppn5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9416ebcac9dac896 |
|
VISUAL
aHash
|
fd0606060606ffff |
|
VISUAL
dHash
|
61ccecccccdc1813 |
|
VISUAL
wHash
|
fd0606060604ffff |
|
VISUAL
colorHash
|
0e0000001c0 |
|
VISUAL
cropResistant
|
0021496161c9014a,96d6e8b094710d8e,80181a2f2c131313,ccccacccccecccec |
• Threat: Phishing
• Target: Users of Immediate Ewave
• Method: Impersonation through a fake website.
• Exfil: Email, Name, phone.
• Indicators: Unrelated domain, form present, Javascript obfuscation.
• Risk: HIGH
The website attempts to harvest user's personal information by having them fill out a form.
Pages with identical visual appearance (based on perceptual hash)