Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10D31D030506A5C26AA83DAEC73E4560B36D5C213CF83261153F8C35E59DBE81DE693C5 |
|
CONTENT
ssdeep
|
24:n/CExWUhs4hjXB9WhYwgJYSXxF4OadIMwN9uAlcyHHcnQ7uxPoYSBu72lS:nJWUPho1kRFLayjHVlZ80+Pf2U |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9999cc6666333399 |
|
VISUAL
aHash
|
181c180018000000 |
|
VISUAL
dHash
|
30b2b24c30040000 |
|
VISUAL
wHash
|
fcfcfce420303030 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
30b2b24c30040000 |
โข Threat: Phishing
โข Target: Unspecified
โข Method: Credential Harvesting
โข Exfil: Telegram
โข Indicators: Recent domain, generic login page, JavaScript, obfuscation.
โข Risk: High
The site attempts to steal user credentials through a fake login form. The information gathered can be used for unauthorized access.
Stolen credentials will be sent to the attackers through a Telegram bot. The use of a Telegram bot allows for stealthy and automated transfer of information.
| ID | Portuguese | English | Trigger |
|---|---|---|---|
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain