Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B752A364230C192D601747C4FFA5F779639EA396E31D501CE0AE22629783DD5ECB3AB8 |
|
CONTENT
ssdeep
|
96:R39GS27MrS2eSTuliZqj1ufcya/koXLk77mbukPVieu7mbp5Vi77mbAfViq7mbOc:FNbW8+iZqUUN7+ciMihiai8pFF6/5pHT |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8cccad3333332766 |
|
VISUAL
aHash
|
8018381800000081 |
|
VISUAL
dHash
|
13b0213101110013 |
|
VISUAL
wHash
|
813cff000cff00ff |
|
VISUAL
colorHash
|
38007000000 |
|
VISUAL
cropResistant
|
13b0213101110013 |
⢠Threat: Phishing/Impersonation
⢠Target: DogeUB (Proxy/Unblocker)
⢠Method: Domain spoofing via randomized subdomains
⢠Exfil: JavaScript-based data capture
⢠Indicators: Malicious JS obfuscation detected
⢠Risk: High due to credential/session theft potential
The site uses obfuscated JS to intercept user input and browser data before forwarding it to external C2 servers.
The site acts as a proxy to monitor all unencrypted traffic from the user's browser.
Pages with identical visual appearance (based on perceptual hash)