Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11C628733230C88370B239F9CA9D1B7199487922FCBA96CC1D499C6996DC3FE58E5405F |
|
CONTENT
ssdeep
|
384:KPyxeHW6abOZATAG8p58nIt8QainYjrfX9RF6WNeTUlvfUfZfBfxz:KPyxeHW6abOyTAG8p58nVAebSUlHG9l9 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
931319395333735b |
|
VISUAL
aHash
|
00ff3c24ffffffff |
|
VISUAL
dHash
|
49326969700e3200 |
|
VISUAL
wHash
|
000808003fffffff |
|
VISUAL
colorHash
|
07007000000 |
|
VISUAL
cropResistant
|
10306868100e2200,26195ac949494639 |
โข Threat: Phishing
โข Target: Facebook users
โข Method: Impersonation via a fake login page
โข Exfil: https://www.wk.pl/login/device-based/regular/login/?login_attempt=1&lwv=110
โข Indicators: Domain mismatch, JavaScript obfuscation, form submission.
โข Risk: High
The attacker creates a fake login page that mimics the legitimate site. When the user enters their credentials, they are sent to the attacker.
Pages with identical visual appearance (based on perceptual hash)