Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DAF1B82112082E3DBD53CE94F6D0B719637ED289D92F942CE5ED407A2EC7CA5C82B5E4 |
|
CONTENT
ssdeep
|
192:JzDoUsYZzZ5ZZLrZ5Zzi5ZZTrVxWhBoJ7RtXBVDY9:dcwhrjZgrVxkBodZ4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b399cc2699996666 |
|
VISUAL
aHash
|
ffe7e7ffe7e7ffff |
|
VISUAL
dHash
|
10080c324c4d3008 |
|
VISUAL
wHash
|
0f07031b1b03233b |
|
VISUAL
colorHash
|
07007000000 |
|
VISUAL
cropResistant
|
10080c324c4d3008 |
• Threat: Phishing
• Target: Unspecified
• Method: Credential Harvesting
• Exfil: ufgnfkitoqnhdaoubird.supabase.co
• Indicators: Recent domain, Form, Obfuscation, Supabase
• Risk: High
The attacker is attempting to steal user credentials through a fake login page. The form fields will likely submit the data to the attackers controlled server.
The Javascript code is used to perform actions such as submit the form to a malicious endpoint or for obfuscation.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain