Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T104A165A044686E5F122360DDFAE6678F3293D319C7CC1A1028F5C2EA1ADBD7CD4DB096 |
|
CONTENT
ssdeep
|
48:cuprnA9ci82yrMw5wS7uFJldAtSnGX9dJ8YlB5nRtVsjfB6IvY62/Vs51BHoMn0i:cuFD7uFlTGNlnRkkV6tvn0LqvnXIyfj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cccc663333999933 |
|
VISUAL
aHash
|
1818181800000000 |
|
VISUAL
dHash
|
303232320c100000 |
|
VISUAL
wHash
|
1f1f1f1f00000000 |
|
VISUAL
colorHash
|
380000001c0 |
|
VISUAL
cropResistant
|
303232320c100000 |
• Threat: Credential harvesting phishing
• Target: Disney+ users
• Method: Fake Disney+ login page to steal email and password
• Exfil: Likely data is sent to a server controlled by the attacker
• Indicators: Unofficial domain (nmbghfgdrtuyjh.wpenginepowered.com), impersonation of Disney+ login page
• Risk: HIGH - Credentials are at risk of immediate theft
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain