Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E941C0B10204641B1BC3AAD085C37E4B95F3ECEBE2591CD856E941AC4ED4BB1E4D07E5 |
|
CONTENT
ssdeep
|
48:H5tSxAcTNmTNMTNmTNMwGDPG37jG3GAOARAWG+OAkVwKyZ6IGmOoGIT30kUexCj:ZbkDu37SWAZRAX+ZkVwKyZOmNGIjAexI |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e63366336699cc32 |
|
VISUAL
aHash
|
e7e7e7e7e7e7e7e7 |
|
VISUAL
dHash
|
4d4d4d4d4d4d4d4d |
|
VISUAL
wHash
|
c3c3c3c3c3c3c3c3 |
|
VISUAL
colorHash
|
060000000b8 |
|
VISUAL
cropResistant
|
0202020202020202,a0a0a0a0a0a0a0a0,a2147061066905a4 |
• Threat: Phishing
• Target: AT&T customers
• Method: Impersonation and PIN code harvesting
• Exfil: Potentially SMS or other methods depending on the backend, confirmed to be obfuscated.
• Indicators: Domain, request for a PIN, brand impersonation, obfuscation.
• Risk: HIGH
The attacker attempts to collect the victims' PIN by mimicking the AT&T brand via SMS in order to gain account access or use the PIN for fraudulent activities.
The attacker may use a sense of urgency to get the user to enter their PIN.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain