Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18D6185F3C200CC1F1752C06449A1BD5A016681CBCA5C2E2262F892EF19DAEF4D9733B6 |
|
CONTENT
ssdeep
|
48:nbVpbfdspa3SJgBHor9iQoI2wCiPDTscPIaN5806Iq:nh3cJ+IGTIIaNy |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
912d7885f45a2eda |
|
VISUAL
aHash
|
434300007e7efcc3 |
|
VISUAL
dHash
|
969679968aaae98a |
|
VISUAL
wHash
|
43430000fffffcc3 |
|
VISUAL
colorHash
|
090000001c0 |
|
VISUAL
cropResistant
|
d4f4e9b3b4ed7301,3999d69696d6e626,96963269664eb9a9,9b153728287575b0,232ce2d296725a9a,58cac66e46c48566,9696326126a6a4a4,243454ac26d2ed6d,929293952664e452,2929a5b786965656,3a3ab533555525a4,cba333a0a0b136b8,969679968aaae98a |
• Threat: Phishing
• Target: BRI customers
• Method: Impersonation via suspicious domain
• Exfil: Unclear, likely data or credentials
• Indicators: Mismatched domain, promotion text, unknown origin
• Risk: High
The attacker is likely attempting to steal login credentials or other sensitive information by mimicking the appearance of BRI and offering an incentive to participate.
The attackers are using a promotion (prize) to trick the user into engaging with the site.
Pages with identical visual appearance (based on perceptual hash)