Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E8D31072B5012D7F6787BE96E5267F05F2918235F40B1784FBA9090E4FC2FE5A226324 |
|
CONTENT
ssdeep
|
3072:BmgGFRFuzwsIEC6IX9ZFcOg3aT/ww1JUSJLKgNd5TuXY7C/2H/aVhmhuMu3Awqta:BmgGFRFuzwsIEC6IX9ZFcOg3aT/ww1tA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a206b8b833c7fccc |
|
VISUAL
aHash
|
ff21302061ffffdf |
|
VISUAL
dHash
|
1fc5e7cf8f22c51a |
|
VISUAL
wHash
|
ef00202001ffffcf |
|
VISUAL
colorHash
|
07600000080 |
|
VISUAL
cropResistant
|
1fc5e7cf8f22c51a,4efced6dcded9cb7,456d24042e2e1b59,6100213d23a78393 |
โข Threat: Phishing
โข Target: Capital One customers
โข Method: Impersonation through a look-alike website hosted on a free platform
โข Exfil: Potentially credentials or sensitive information
โข Indicators: Free hosting and brand logo
โข Risk: High
The attacker aims to steal user credentials (username and password) by creating a fake login page that closely resembles the legitimate Capital One website.
Found 10 other scans for this domain