Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B1818632934CAA7CD6C28B485625301936D5D5C9F266919CC7FF96479582DF0C8B48BC |
|
CONTENT
ssdeep
|
48:nwJV3BbSwyd41O66qJCtOfYxyfMlof5OxJXC9ofCH2HwfL8s8Ug8OmaYiepHN:nwf3p6ECYKyUlEiJXIoVHwVk4iW |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a226061b19ddcdcf |
|
VISUAL
aHash
|
0000f7cfffffffe7 |
|
VISUAL
dHash
|
fbcd27161002000c |
|
VISUAL
wHash
|
0000c3c3ffffff00 |
|
VISUAL
colorHash
|
070c00000c0 |
|
VISUAL
cropResistant
|
fbcd27161002000c |
⢠Threat: Phishing
⢠Target: Cembra customers
⢠Method: Impersonation via login page.
⢠Exfil: Form data
⢠Indicators: Domain age, domain mismatch, form detected.
⢠Risk: High
The attacker is attempting to steal user credentials by mimicking a legitimate login page. Users entering their username and password will have their credentials harvested.
Pages with identical visual appearance (based on perceptual hash)