Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T198036196310866E5C2F38FD894102A906146EF5FC9718770C2BC4E3A6BE35A57798F3E |
|
CONTENT
ssdeep
|
768:j0nZwXEOxUK2cSzZdEaxEKCCVmJE85WsEDPSIG0Mf+fWxGW1hs4jY7yUjJoHVK1:j0nZwXrm1cSzZd7yBCVmJ7MzDPSNV2fR |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
add2a5d2cc8dd2a1 |
|
VISUAL
aHash
|
ff0c7f1800000303 |
|
VISUAL
dHash
|
b339faf236721676 |
|
VISUAL
wHash
|
ffff7f1f00000303 |
|
VISUAL
colorHash
|
1bc00000040 |
|
VISUAL
cropResistant
|
06061e9e0c060608,8290baa6acb0888a,b199f2f237761676 |
• Threat: TikTok brand impersonation phishing
• Target: Users potentially interested in TikTok shops
• Method: Fake website with contact form to collect user data
• Exfil: Data likely sent to a custom API (based on obfuscation)
• Indicators: Recent domain registration, brand impersonation, domain mismatch, presence of forms, javascript obfuscation.
• Risk: HIGH - Potential for data harvesting.
Pages with identical visual appearance (based on perceptual hash)