Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11AB3BD234159752A4437C3C0307A5B3BE5A6999FFAE70A004EDCC7F62BF9CA0741A66D |
|
CONTENT
ssdeep
|
1536:NukutpR4nXBKpSpFl26vl0ZLGxaLYYd9UyFI2X/5:NEUMcEUYd9UyTX/5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93076d0353177f0d |
|
VISUAL
aHash
|
001f0f2e6f0f01c7 |
|
VISUAL
dHash
|
dcbf38dcdcbcb30f |
|
VISUAL
wHash
|
000f0f3f7f0f01e7 |
|
VISUAL
colorHash
|
00003400400 |
|
VISUAL
cropResistant
|
fdb7fcdcdcbdf30f,dcbf38dcdcdcb377,88535393251bc9c8,4e8f91c1a7a6ceca,68000c32320c21d4 |
โข Threat: Phishing
โข Target: Equinoxis Drive AI users
โข Method: Credential Harvesting
โข Exfil: https://equinoxisdriveaiupdates.com/assets/submit.php
โข Indicators: Domain, form requesting information, JavaScript Obfuscation
โข Risk: HIGH
The site collects user's PII (name, email) with the intention of using them to impersonate the user or conduct other attacks.
Use of atob, fromCharCode, and unicode_escape to evade detection.
Pages with identical visual appearance (based on perceptual hash)