Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12141CEB10204641B1BC3AAD085C77F4B95F3ECEBE2992CE856E941AC4ED0BB5E4D07E5 |
|
CONTENT
ssdeep
|
48:H5GSxAcTNmTNMTNmTNMwGDPG37jG3GAOARAWG+OAkVwKyZ6IGmOoGIT30kUexCj:Z+kDu37SWAZRAX+ZkVwKyZOmNGIjAexI |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e63366336699cc32 |
|
VISUAL
aHash
|
e7e7e7e7e7e7e7e7 |
|
VISUAL
dHash
|
4d4d4d4d4d4d4d4d |
|
VISUAL
wHash
|
c3c3c3c3c3c3c3c3 |
|
VISUAL
colorHash
|
060000000b8 |
|
VISUAL
cropResistant
|
0202020202020202,a0a0a0a0a0a0a0a0,a2147061066905a4 |
• Threat: Phishing
• Target: AT&T customers
• Method: Impersonation via a lookalike website
• Exfil: Unknown, likely credential harvesting and potential personal data
• Indicators: Domain mismatch, use of AT&T branding, obfuscation.
• Risk: HIGH
The attacker likely uses a fake login page to trick users into entering their AT&T credentials, possibly including a PIN or verification codes. This information is then used to gain access to the user's AT&T account.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain