Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19A43618772447AA5C1B34AC894106494A287EF5FCA60C770C56D0E3A2BA36B477D9F3F |
|
CONTENT
ssdeep
|
1536:ytMb41LAgsfYDm82zxEHXe9k9AEaWdXPtN611p1bK2YkBLVaAanjps5M7S8:y8EFd/nUTl/dhcA8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c7d2bd3cfe885280 |
|
VISUAL
aHash
|
9c3c7c7c64000383 |
|
VISUAL
dHash
|
30e8c9c8c832b216 |
|
VISUAL
wHash
|
bc7c7c7e7c001383 |
|
VISUAL
colorHash
|
32000098000 |
|
VISUAL
cropResistant
|
8092d683ad9392a8,30e8c9c8c832b216 |
⢠Threat: Brand Impersonation/Fraud
⢠Target: Xfinity consumers
⢠Method: Charitable facade
⢠Exfil: Likely donation/PII harvest
⢠Indicators: Unrelated foundation using known corporate branding
⢠Risk: High
The site uses a reputable corporate name to create a false sense of security, likely leading to payment processing or data harvesting.
Registering a foundation-related TLD with a major corporate name.