Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15D52E97101006E3F82C586D8E2B9770B3682C2D7C6464784D3F5879FADD9DE2DC2AA9D |
|
CONTENT
ssdeep
|
192:LFqGYXIjJFLJHAlm121lBVxlWxab1Wgl48qlBbtaH/G6os+NJHAlm125lBV/lWxj:LFnSWmRRx91bqm9R/91Vy |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ece4339966329933 |
|
VISUAL
aHash
|
ffdbc3d352180000 |
|
VISUAL
dHash
|
96969696b6b21212 |
|
VISUAL
wHash
|
ffdbdbd3d3180000 |
|
VISUAL
colorHash
|
38000000e00 |
|
VISUAL
cropResistant
|
96969696b6b21212 |
โข Threat: Phishing
โข Target: Spotify users
โข Method: Impersonation via a fake login page.
โข Exfil: login.php (based on form actions)
โข Indicators: Unrelated domain, form present, obfuscated code.
โข Risk: HIGH
The attackers are using a fake Spotify login page hosted on a different domain (eat-co.com) to steal user credentials. Users are tricked into entering their login information, which is then sent to the attackers.