Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11BD17335A4195D2A0713EBC1F3A2737AD293C289C7560D0495FC47EE0BEAE95CC5A323 |
|
CONTENT
ssdeep
|
96:Ws0lGTGiSGvRGmGmIKWGlHtCrFzbX2BRGxR6EkopXPFssPbG/ZC0myJ:WsysnS6RfRWKHSofMR6EkcbGSa |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc34636167366963 |
|
VISUAL
aHash
|
00ffffff0000ffff |
|
VISUAL
dHash
|
1e003020223a0400 |
|
VISUAL
wHash
|
00ffdfdf0000c0ff |
|
VISUAL
colorHash
|
070000003c0 |
|
VISUAL
cropResistant
|
3a203228323a0c00,403048484a489616 |
• Threat: Credential harvesting phishing targeting UK government users.
• Target: Users of GOV.UK services, specifically those related to The Insolvency Service.
• Method: Presents a fake login form to steal usernames and passwords.
• Exfil: Unknown data exfiltration point.
• Indicators: Domain mismatch (admin-ods.insolvency-development.co.uk vs. gov.uk), login form.
• Risk: HIGH - Immediate risk of credential theft and potential unauthorized access to government services.
Pages with identical visual appearance (based on perceptual hash)
Found 3 other scans for this domain