Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F803B8B052045A3DA143C3ECD732377A32BA91D5EB0B121AC6F857789A85CDAEC375D8 |
|
CONTENT
ssdeep
|
384:ysKQsWsr1S96KtpWKnP0bDhT1Pyt/wFKBKcxjmLAvgu3KR4X4+BTgAZK:yjQDaiL0bD/cwFUsRCj1K |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cccccc6633333399 |
|
VISUAL
aHash
|
005a180000000000 |
|
VISUAL
dHash
|
0030100000000000 |
|
VISUAL
wHash
|
ffffffff00000000 |
|
VISUAL
colorHash
|
38000000000 |
|
VISUAL
cropResistant
|
0030100000000000 |
• Threat: Impersonation phishing
• Target: X/Twitter users
• Method: Displaying a fake verification message and possibly prompting for credentials.
• Exfil: Unknown, likely to steal credentials
• Indicators: Domain unrelated to X, brand impersonation, obfuscated code
• Risk: High
The site impersonates X/Twitter and displays a 'verification complete' message. This can lull users into a false sense of security, possibly followed by a redirect to a login form that harvests credentials.
The site uses Javascript obfuscation to hide potentially malicious actions like credential harvesting.
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain