Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12D3162B1A022983706A7D5D2A4F5835F22D28B1DEB47065287FC83DC4BEBDC5FD12181 |
|
CONTENT
ssdeep
|
48:i2UtVSZSZSZSipZkAx8KuA5CtjBaTCz+eBoA1Sx5Aw3C11:YtVSZSZSZSipZrdWAUSxPCv |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9b4f0e8531b9c6cc |
|
VISUAL
aHash
|
3d3c3ccbcbffd981 |
|
VISUAL
dHash
|
7979691716b93b3b |
|
VISUAL
wHash
|
3d3c3889c3df9981 |
|
VISUAL
colorHash
|
07000e00000 |
|
VISUAL
cropResistant
|
7979691716b93b3b |
• Threat: Phishing/Malicious Redirect
• Target: Generic user
• Method: Browser gate/loading screen trickery
• Exfil: Likely redirection to secondary phishing site
• Indicators: Extremely new domain (1 day old)
• Risk: Moderate
Uses a 'security' loading page to delay the user while likely setting tracking cookies or preparing a redirection to a specific phishing landing page.
Determining if the user is a bot or a target before revealing final content.
Pages with identical visual appearance (based on perceptual hash)