Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10C515419301D4F37A25B1EF41A9A7F153BCDB5F3C4404E3C40F49AAC5AA1F198AA3944 |
|
CONTENT
ssdeep
|
48:DC4wYPIGyKqPKcNTKe92aOEhNWDDWDVWDjxGWDgWD6RgWDCTWDaWDM6WDkcbqqcf:rXqiGTKe5WDDWDVWD0WDgWDxWDCTWDau |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cccc333399cc6633 |
|
VISUAL
aHash
|
0000001818000000 |
|
VISUAL
dHash
|
00100cb2b2040800 |
|
VISUAL
wHash
|
000000181b030303 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
82a2b0a2aa33338a,00100cb2b2040800 |
• Threat: Credential harvesting phishing attack.
• Target: Pritunl users.
• Method: Fake login page designed to steal usernames and passwords.
• Exfil: Data is likely being sent to a malicious server controlled by the attacker.
• Indicators: The URL uses a free dynamic DNS service, the domain doesn't match the official Pritunl website, and there are forms for submitting login credentials.
• Risk: HIGH - Credentials entered on this page will likely be stolen and used to access the user's Pritunl account.
Pages with identical visual appearance (based on perceptual hash)