Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EB81533064216077139B4EE9B4F57B0E32ABC35ECA43141836AC93D41BF6EF9DC2A569 |
|
CONTENT
ssdeep
|
96:nqZeEM44xke4Nbt6lS4I0sjM+3Cq7VorGM:KeEJNYlSuyvNyd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9c3332cd1dcd9836 |
|
VISUAL
aHash
|
02041e1a1efbfa00 |
|
VISUAL
dHash
|
565cb0b2b2b2a6ac |
|
VISUAL
wHash
|
02041e1e1fffff04 |
|
VISUAL
colorHash
|
06007000000 |
|
VISUAL
cropResistant
|
b2f2b0333380b286,565cb0b2b2b2a6ac |
• Threat: Credential harvesting phishing attack
• Target: Kiatnakin Phatra Bank customers
• Method: Fake login form stealing email and password
• Exfil: Data sent to /landingpages/99897ef0-5700-48f4-9c83-b686955ea6bc/2vyfuk9ib87ezawxnl_plkl7rarq2ynvezowt-rsjxg
• Indicators: Domain mismatch, suspicious URL, form submission via JavaScript
• Risk: HIGH - Immediate credential theft
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain