Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E152CAB2A5409D770593D3E6E771B76F76C18786CA9322C2E2F8D38C1BC6EA6DC51204 |
|
CONTENT
ssdeep
|
192:iY/SsjwPJnaYy4vRloE40+JrrFPfVl1li2HvHf9G3b8Ek0RclAlBYoTGBxuq:QY9NrZVrl3vHf9GAvGAUq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e165646464cf9b9a |
|
VISUAL
aHash
|
c3c3ffffffffffff |
|
VISUAL
dHash
|
869641492a140000 |
|
VISUAL
wHash
|
c3c3c7bc80e2f0f0 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
869641492a140000,5048888880200000 |
⢠Threat: Phishing/Impersonation
⢠Target: Facebook
⢠Method: Hosted on Blogger using misleading branding
⢠Exfil: Obfuscated JS form submission
⢠Indicators: Domain mismatch, suspicious JS
⢠Risk: Moderate
The site uses obfuscated JavaScript to submit forms, potentially capturing user input for account takeover.
Leveraging established brand trust on free hosting platforms.