Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11EF32BCDB6E1702643A3A4B5603F414FB13AB866A44C84A4B19CD8E47F74DA94277FBC |
|
CONTENT
ssdeep
|
1536:fa+TFSzL751Jqc2HyP0SuRPmym0pO1s8dsR5qxyzT/ghgOKWYZjAartrvpD3pdug:fa+TFpuydkXiR5zzTq+bxpD3ZV49pcv |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92929a9a9e9e9696 |
|
VISUAL
aHash
|
3c66660000000000 |
|
VISUAL
dHash
|
71cccc9641100000 |
|
VISUAL
wHash
|
ffffe7e781180000 |
|
VISUAL
colorHash
|
30007000000 |
|
VISUAL
cropResistant
|
a0c0b06764688020,71cccc9641100000 |
• Threat: Domain parking/expiration notice.
• Target: Anyone visiting the expired domain.
• Method: Displaying a landing page with information about domain expiration and Dynadot services.
• Exfil: No data exfiltration involved.
• Indicators: Domain parking page, expired domain.
• Risk: LOW - Informational page, no malicious activity.
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain