Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1901273B2C044AC530E13D6FEF256274AF583C11DCEE3AD0186DDD7990AF9CE2865A1B5 |
|
CONTENT
ssdeep
|
192:R0h3sOzHlpNtdma+y4Kq4GxI6eZYakFS0/p8YQ9D9eEo:Kh35zFpNtdma+y4Kq4GxI6aYa2/K7heJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bf3e70610f4f6160 |
|
VISUAL
aHash
|
00ffffbfffffffff |
|
VISUAL
dHash
|
3030286860000020 |
|
VISUAL
wHash
|
000087873f3fff81 |
|
VISUAL
colorHash
|
07000038000 |
|
VISUAL
cropResistant
|
3838286800402060,0080808080800000 |
โข Threat: Phishing
โข Target: Orange customers
โข Method: Impersonation via a fake login page.
โข Exfil: https://api.staticforms.xyz/submit
โข Indicators: Free hosting, brand logo, form submission.
โข Risk: High
The attacker creates a fake login page that mimics the Orange login page. Users are tricked into entering their credentials, which are then harvested by the attacker.
loader.js?target_type=notice&target=qQMjK8bGPages with identical visual appearance (based on perceptual hash)