Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11FF1FFF1D054ED3B071286C4EBB56B4B7661C785CB430A4553F482ABAFCADB0CE225AD |
|
CONTENT
ssdeep
|
192:QpjLo4c7QzD0k8iIIWyWdWKXqSdyvkYMfOawQQ:QpjLo4LX1XWzdBdKFMfOay |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e4669b9b4f989864 |
|
VISUAL
aHash
|
ffe3e3e3e3ffff00 |
|
VISUAL
dHash
|
0e062626070a0000 |
|
VISUAL
wHash
|
e7c3c383e3ff3000 |
|
VISUAL
colorHash
|
07000000030 |
|
VISUAL
cropResistant
|
0e062626070a0000 |
โข Threat: Phishing
โข Target: Xfinity users
โข Method: Impersonation through a fake login page on free hosting
โข Exfil: https://xxxxffinniityyy.weebly.com/ajax/apps/formSubmitAjax.php
โข Indicators: Weebly hosting, Xfinity logo, login form, obfuscation.
โข Risk: High
The site uses a fake login page to steal Xfinity user credentials.
Pages with identical visual appearance (based on perceptual hash)