Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E6A3BF234269352A4537C3C1347A6B7BD1A6D98FFAE709010EECCBFA26F9C90741A51D |
|
CONTENT
ssdeep
|
768:U/EtpR4nXF6YjOpSpFlTC6rrWFJbHhQrENR/Mau:U8tpR4nXBKpSpFl26vQJjhnL/Mau |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93036d13d30f6d0f |
|
VISUAL
aHash
|
000f077e6e0f01f7 |
|
VISUAL
dHash
|
d8bd7cdcdcbcf70f |
|
VISUAL
wHash
|
000f037f3f0f01ff |
|
VISUAL
colorHash
|
00003400400 |
|
VISUAL
cropResistant
|
fd37fcdcdcbdf707,d8bd37dcdcdcb777,d44b49d26d4d6d32,072305170e1c3424,d8100c3232080001 |
โข Threat: Phishing
โข Target: Users of Ryphor Mercado App
โข Method: Credential Harvesting via Form
โข Exfil: https://the-ryphormercadoapp-news.com/assets/submit.php
โข Indicators: Unrelated Domain, Form asking personal info, Javascript Obfuscation
โข Risk: Alto
The attacker aims to steal user credentials by presenting a fake login form on a website with a deceptive domain name. User enters their PII.
Pages with identical visual appearance (based on perceptual hash)