Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C902866090BA6D3F520781EDA7A52F12A6A7C345CBD34226C2FED78C0FE9C51DB02554 |
|
CONTENT
ssdeep
|
192:nnG6Zmzd3LnRumGqnR4Y06GY4T4s3ogQF:nGcOd3LnRumGqnR4Y06Gn8+oPF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cccc333366cccc99 |
|
VISUAL
aHash
|
1818181800000000 |
|
VISUAL
dHash
|
3032b23210000000 |
|
VISUAL
wHash
|
1c1c1c1c1c1c0c0c |
|
VISUAL
colorHash
|
00000038000 |
|
VISUAL
cropResistant
|
8080808080808080,808080c0c0808080,3032b23210000000 |
โข Threat: Credential Phishing
โข Target: SwissPass users
โข Method: Imitating the login page to steal credentials.
โข Exfil: s/1.php
โข Indicators: Forms, obfuscated code, domain mismatch.
โข Risk: HIGH
The attacker is using a fake login page that mimics SwissPass's appearance to trick users into entering their email and password. This is a common tactic to obtain credentials and gain access to the victim's account.
The use of javascript to send the collected credentials to a malicious backend. Atob and eval are known techniques for hiding malicious code.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain