Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C08152A08208597B15B6C4FCDAE7B30F63D0C143CA1609110AFC5BAE1ED3EE5DDA725A |
|
CONTENT
ssdeep
|
48:nGpYWE1rINxJ5G1C1fpfE4+wv+yMrbseaUXvHb5PvROO7zRlaVQ7u/+k0cx0QAQc:nGzL+4+yMrbkUXDqsmYu/+SAY/ldtNg |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f722f7d57b088888 |
|
VISUAL
aHash
|
ffffff00ffffffff |
|
VISUAL
dHash
|
080890490c100808 |
|
VISUAL
wHash
|
f0e0ff00f3f30000 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
080890490c100808,0000001010101000 |
⢠Threat: Phishing
⢠Target: Facebook users
⢠Method: Impersonation via domain spoofing
⢠Exfil: Credentials (email/phone and password)
⢠Indicators: Mismatched domain, Facebook branding, login form
⢠Risk: High
The attacker aims to steal user credentials (email/phone and password) by impersonating Facebook's login page. Users are tricked into entering their information, which is then sent to the attacker.
The attacker uses social engineering to create a sense of trust by using Facebook's branding and layout, and presenting a familiar login page.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain