Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1313396335014652B0633C2C035B5673EE296A64FD2B30E8557FCC7AE0BD5DEA9D2B229 |
|
CONTENT
ssdeep
|
768:e2+NjJ3wlJhBOWlp0tkmcM46rUUnGOnWMyaM:QtwlJhRpGfa0GqcaM |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9515e26e4e6a7ac4 |
|
VISUAL
aHash
|
000e0e0e0e81ffff |
|
VISUAL
dHash
|
98dc1838381f1f33 |
|
VISUAL
wHash
|
004e0e0e8e81ffff |
|
VISUAL
colorHash
|
06002040080 |
|
VISUAL
cropResistant
|
dc183c38381f0c33,7c5c9c4c6d6d6c6e,93dcd8183838381b |
• Threat: Phishing
• Target: Users of Movo Stack Mode
• Method: Forms to steal personal data
• Exfil: Sharing of data with partners potentially including malicious actors
• Indicators: Domain name, form, consent for data sharing
• Risk: Moderate
The site mimics a brand or service (Movo Stack Mode) with a look-alike design and form, aiming to trick users into entering their personal information. Collected data is shared with partners.
The form actively collects personal information which can be sold or used in further phishing attacks or other malicious activities.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain