Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19581ABB30701144D6F82F9C4A4227F19955BC22DE54FC86CF2EE597A67C4FB0C690AA5 |
|
CONTENT
ssdeep
|
48:WhHceGT3ZAzrJUekd0dv/iK8NkAVn1aIi53LImr+pVUi8zf013xK0qF+t355oEYz:vEtHk2LGmrWui8mFk+tp5oh4Enzl |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a6764c0d59193377 |
|
VISUAL
aHash
|
00ffffffffff1fff |
|
VISUAL
dHash
|
80080c0c08ec7000 |
|
VISUAL
wHash
|
00e7e7ffff0f0000 |
|
VISUAL
colorHash
|
07202000080 |
|
VISUAL
cropResistant
|
8c0c0c0c08783000,0000014141018000 |
⢠Threat: Credential harvesting phishing kit
⢠Target: Apple users worldwide
⢠Method: Fake Apple ID login form stealing credentials
⢠Exfil: Data sent to unknown server via JavaScript
⢠Indicators: Free hosting, domain mismatch, obfuscated JavaScript
⢠Risk: HIGH - Immediate credential theft
Pages with identical visual appearance (based on perceptual hash)
Found 4 other scans for this domain