Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12D91B632D1502973687BC352EEE1524A4223DF9DE7130AE2CAD0053AD64CDADDCE60AD |
|
CONTENT
ssdeep
|
96:n909TBn9YLfqtqC8PLb8So8WZLhAyKGlg:y9TZmWLhJKGlg |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
99996666666698ce |
|
VISUAL
aHash
|
0018181818180000 |
|
VISUAL
dHash
|
00b2b23270703010 |
|
VISUAL
wHash
|
183c3c3c3c3c3c18 |
|
VISUAL
colorHash
|
38000000c00 |
|
VISUAL
cropResistant
|
b4b2b3b3b333b0f0,00b2b23270703010 |
โข Threat: Malware distribution/Suspicious activity
โข Target: yamShare users
โข Method: Malicious URL redirect/Clickjacking
โข Exfil: Unknown, but JavaScript indicates potential data exfiltration.
โข Indicators: Domain detected as malicious by CRDF; JavaScript obfuscation and form submission.
โข Risk: Alto
The site is flagged as malicious, and it's likely serving a malicious payload. The obfuscated Javascript may also indicate clickjacking.
The site could be used to trick a user to click something on a different page or to redirect them elsewhere.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain