Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T177B1C7FFDB50306D19524578FFA6F848DB6B069997D222D4608C41BD33CC724517F0AA |
|
CONTENT
ssdeep
|
96:TUL9S94u+NTHyKsjX8iDCEwt50NTB6lwT4X/VoLx2o2l:wen+1NjK1BIwE/689l |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c33e4c2e383c2cf3 |
|
VISUAL
aHash
|
307c78607c707868 |
|
VISUAL
dHash
|
c0c0c0d0c8c0c0c0 |
|
VISUAL
wHash
|
707c78687c707c78 |
|
VISUAL
colorHash
|
00007000000 |
|
VISUAL
cropResistant
|
c0c0c0d0c8c0c0c0 |
• Threat: Phishing/Impersonation
• Target: Facebook users
• Method: Typosquatting/Unrelated domain
• Exfil: Credential harvesting
• Indicators: Official takedown notice confirms fraud
• Risk: High
The site mimics the Facebook login page to capture user credentials.
Uses a deceptive domain name containing 'facebook' to trick users.
Pages with identical visual appearance (based on perceptual hash)