Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T160F164626168383B427792CDBF92FF19C4E7C13BCA092C0186EC9B9D1ED5EE0D94425A |
|
CONTENT
ssdeep
|
96:cZfYIkzIoN5W4QkQC7JXntEGvEhW8jAYrZizaYO+0EtAlmTia5K2nDRA1Uebmw0r:oAI8IAbZl8l9f+0EtQmTLzeawRY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b2b5189e199ec734 |
|
VISUAL
aHash
|
ffc3e7ffffff0000 |
|
VISUAL
dHash
|
238e8e001408acd0 |
|
VISUAL
wHash
|
9f83c3f7e7e70000 |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
230e8e0c0c140c0c,13eae81380aed4d0,a0e0f4b4c9c9d2d0 |
• Threat: Phishing
• Target: French citizens
• Method: Impersonation and Data theft
• Exfil: Telegram Bot
• Indicators: Domain mismatch, Form, Obfuscation
• Risk: Critical
The attacker is using a fake website to steal login credentials and personal information. The user is tricked into entering their information, which is then sent to the attacker.
The attacker leverages the brand image of amendes.gouv.fr to increase the chances of the victim entering their information.
| ID | Portuguese | English | Trigger |
|---|---|---|---|
Pages with identical visual appearance (based on perceptual hash)
Found 3 other scans for this domain