Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D44133B472543EF74E93A2D67F82A7C3B2D28089F1120A1C22F8D39A1BDEEB4D519445 |
|
CONTENT
ssdeep
|
48:uJYgcCGOnZvW3u3bXY0YZTgTqRguZNSTd3OmIW:GYEGOnZvW3u3bxY6WRguipHb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b7831d8137833f83 |
|
VISUAL
aHash
|
ffffffffffffff00 |
|
VISUAL
dHash
|
c8000c0c0c080028 |
|
VISUAL
wHash
|
00ffc7c7e0f0f000 |
|
VISUAL
colorHash
|
07000000038 |
|
VISUAL
cropResistant
|
c000080c0c0c0008,00c8203e1e210880 |
• Threat: Phishing
• Target: Assurance Maladie (Ameli) users
• Method: Impersonation and credential harvesting.
• Exfil: Unknown
• Indicators: Domain mismatch, security verification
• Risk: High
The site attempts to steal user credentials by mimicking a security verification process. Users are tricked into entering their login details, which are then captured by the attackers.
Pages with identical visual appearance (based on perceptual hash)
Found 3 other scans for this domain