Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D752C97251C1793B474381C291237B5EF2C2C128DB921850EAF887EA9BDECF1D969227 |
|
CONTENT
ssdeep
|
384:+9tiaFsfsvCI5CPnYAfNBTxsJEJuvSf6F93L8k:+HiaFsfsKI52YOxsqGF93L8k |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a887359bd3b1c730 |
|
VISUAL
aHash
|
2f9377ffff3d0000 |
|
VISUAL
dHash
|
dd26e6f9e9611f1f |
|
VISUAL
wHash
|
0f0377ffff3c0000 |
|
VISUAL
colorHash
|
07c00000000 |
|
VISUAL
cropResistant
|
dd36e6f9b961399f,9733397c7e7efebe,693f9f9f1f1fc934 |
⢠Threat: Credential harvesting phishing attack
⢠Target: BNP Paribas employees
⢠Method: Fake login page to steal employee credentials
⢠Exfil: Likely to a malicious server
⢠Indicators: Domain mismatch (bnpparibas.mitarbeitervorteile.de vs bnp.paribas), login form, cookie prompt overlay
⢠Risk: HIGH - Real-time credential theft.
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain