Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11781633064252067134B0EEAB8F53B0E30ABC31EDA47181827EC93D55BF6DF8DC29664 |
|
CONTENT
ssdeep
|
96:nqZeEMa9B4xke4Nbt6lS4I0sjM+3r9Wq7Vm9r9bi9iGM:KeED9VNYlSuyv79Jc9r9bi9o |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9c3332cd1dcd9836 |
|
VISUAL
aHash
|
02041e1a1efbfa00 |
|
VISUAL
dHash
|
565cb0b2b2b2a6ac |
|
VISUAL
wHash
|
02041e1e1fffff04 |
|
VISUAL
colorHash
|
06007000000 |
|
VISUAL
cropResistant
|
b2f2b0333380b286,565cb0b2b2b2a6ac |
• Threat: Credential harvesting phishing
• Target: Kiatnakin Phatra Bank customers
• Method: Fake login form steals email and password
• Exfil: Data sent to unknown endpoint (/landingpages/99897ef0-5700-48f4-9c83-b686955ea6bc/bad98etrhtif_kh2xwmnfcbm02nn5lrogh8avxevrkm)
• Indicators: Domain mismatch, form submission via JavaScript
• Risk: HIGH - Immediate credential theft
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain