Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T111913F215025AE3351E286E4B6DDEB6366EFC228CF80295812FCC2AD0BD5C41B67B954 |
|
CONTENT
ssdeep
|
96:uZ/Oy+IVgExhqPE9tFMhTFk6aMhTtk6Yt:uZ/OOgih2E9tFMhTFk6aMhTtk6k |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9999996666668b33 |
|
VISUAL
aHash
|
1818181800000000 |
|
VISUAL
dHash
|
b2b2b2b24c200000 |
|
VISUAL
wHash
|
3c3c3c3c00000000 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
a2a2e2a296a89696,b2b2b2b24c200000 |
โข Threat: Phishing
โข Target: Email credentials
โข Method: Credential Harvesting
โข Exfil: /?_task=login
โข Indicators: Obfuscation, Form Actions, Suspicious domain
โข Risk: High
The site attempts to steal user credentials by mimicking a login form. The form submits to a suspicious path, indicating an attempt to capture entered data.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain