Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1355263313A9A3B27164316C8BCF3574DA247F33ECA01C445E1F75AE36BE6EA0A485359 |
|
CONTENT
ssdeep
|
192:wRKZTpE5cJOw34dPwmWg+WWSkNEf3n6/Xq66aqCOFHsC2Jx0+SuY3M8AiWJkwp0u:AK/yOz/qfaPOoJ69glWPX1iJwU |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc95b16a936d648d |
|
VISUAL
aHash
|
fffff0f8f0f0f0ff |
|
VISUAL
dHash
|
00017474c1e52780 |
|
VISUAL
wHash
|
fff090103070f0ff |
|
VISUAL
colorHash
|
07280011000 |
|
VISUAL
cropResistant
|
00017474c1e52780,02070707060d1d1a,52b212dac8d8c803,5d4dc5f85e0d0fc1 |
• Threat: Potentially malicious form collecting personal information
• Target: Individuals applying for heat pump subsidies in Hauts-de-Seine, France
• Method: Online form requesting information; potential for data harvesting
• Exfil: Data exfiltration target unknown, but likely a database or API
• Indicators: JavaScript form submission, obfuscated JavaScript, domain 'form.typeform.com'
• Risk: LOW - Requires user interaction; potential for data harvesting if form is malicious
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4288 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 10 other scans for this domain