Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A3222F11111137B7268383B67B31EBED73CA1A99C91B8B0113F8970B6FAEDC1CE1565A |
|
CONTENT
ssdeep
|
96:nWR4BHi0nQDRvlmpQ6Xb13IfzfIM73578IuKyzA/K7if9TKWDugviuz+66mpOJI1:BeA55swghDCu4m+I9Y0P |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b7d8847a31855c76 |
|
VISUAL
aHash
|
ffffffef84803703 |
|
VISUAL
dHash
|
c01960d81d6d4466 |
|
VISUAL
wHash
|
7fffbe0f84002303 |
|
VISUAL
colorHash
|
06007000040 |
|
VISUAL
cropResistant
|
c01960d81d6d4466,2626060e27554102,06971b21355968e8,cadfde8f0e4e6f6b |
• Threat: Brand impersonation phishing
• Target: Discord users
• Method: Displaying Discord branding on a fake website to build trust for potential phishing activities.
• Exfil: N/A (no form visible, but likely aiming for credential theft on future pages)
• Indicators: Free hosting, domain mismatch, Discord branding
• Risk: HIGH - Potential for future credential theft or malware distribution
Pages with identical visual appearance (based on perceptual hash)