Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1416296F6B2C1AD2B932331D8F1D2F3CEF043620EDAC94694B5BD07B552DACB240159A9 |
|
CONTENT
ssdeep
|
384:Hw1F4V+8B1pd/cB3B7PdyC9N9FXWKeWnGoCglYCCgtNC33:Hw12VjB1ncNdoSN/GmYgNC3 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
aa35ca35ca35ca35 |
|
VISUAL
aHash
|
00000000000000ff |
|
VISUAL
dHash
|
0e0e091e1b1f1ec9 |
|
VISUAL
wHash
|
03070b0f0f0f0fff |
|
VISUAL
colorHash
|
00007000000 |
|
VISUAL
cropResistant
|
8d00c9c149c980c9,0e0e091f131b120f |
• Threat: Phishing attempt targeting AT&T customers.
• Target: AT&T customers.
• Method: The attacker uses a domain that does not belong to AT&T, showing AT&T logos to trick users into clicking the button.
• Exfil: Unknown, potentially redirects to another phishing page or steals information on click.
• Indicators: Domain mismatch, AT&T logo, billing information text.
• Risk: MEDIUM - The page could lead to credential harvesting or financial theft.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain