Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FC5309F1209450BB4083CFCDDE33FE1AE2A39CBADF865B8251E9C6255996CD1CE45878 |
|
CONTENT
ssdeep
|
768:sdHIeYK6ev6oOmIyWD1qIiaU00o4zaLPPOYo0LNWON:sdoe6ew19rr0oyeBION |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c35c7c166c176393 |
|
VISUAL
aHash
|
0000ffffffffffff |
|
VISUAL
dHash
|
3432c1e0d8c8c8c2 |
|
VISUAL
wHash
|
00007e7c7e7e7e70 |
|
VISUAL
colorHash
|
06002000c00 |
|
VISUAL
cropResistant
|
53c0c0c8c8c8c8c2,0c8e343334743635 |
• Threat: Phishing
• Target: Riyadh Region Municipality users
• Method: Impersonation through a look-alike website on free hosting.
• Exfil: ./DisplayLicenseDetails.aspx?DisplayMode=2&REQUEST_NUMBER=709DBC2831506513&REQUEST_YEAR=7A4246D8C90FED3F
• Indicators: Free hosting, brand logo, form.
• Risk: Alto
The attacker likely aims to steal user credentials by creating a fake login form that redirects to a malicious server.
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain