Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C213833D11449EBB1183D2F0F375AB7BB298C744C537DA56E2F883660BC6C45CEA62A4 |
|
CONTENT
ssdeep
|
768:x20SeBfV1df1dwhOp2tOdztUde6ASgbdY:4mBfV1df1dwh7t0ztUN6dY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d216e9e93c97b441 |
|
VISUAL
aHash
|
0000040400ffffff |
|
VISUAL
dHash
|
c6ccecaca53a0333 |
|
VISUAL
wHash
|
0004161450ffffff |
|
VISUAL
colorHash
|
1b203010000 |
|
VISUAL
cropResistant
|
808080c0c0808080,80a080b030b080a0,808080f070808080,a800acecaca88080,004a3594ce8a2180,c433330b33033333,d6ccccecececa4a3,1733713171793974 |
• Threat: Credential harvesting phishing kit
• Target: Précieux Valexor users
• Method: Fake login form stealing personal information
• Exfil: Data sent to unofficial endpoint
• Indicators: Domain mismatch, recent domain, obfuscated JavaScript
• Risk: HIGH - Immediate credential theft
Pages with identical visual appearance (based on perceptual hash)