Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T113D19435A4195D360703EB81F7A2637AD1C3C249C6960D05E5FC47AE0BEAE95CC9A327 |
|
CONTENT
ssdeep
|
96:Ws0lGTGiSGvRGmGmIKWGlHtCrFzbX2BRGxR6EkotXPFssekeZC0myJ:WsysnS6RfRWKHSofMR6Ek3Ya |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc34636167366963 |
|
VISUAL
aHash
|
00ffffff0000ffff |
|
VISUAL
dHash
|
1e003020223a0400 |
|
VISUAL
wHash
|
00ffdfdf0000c0ff |
|
VISUAL
colorHash
|
070000003c0 |
|
VISUAL
cropResistant
|
3a203228323a0c00,403048484a489616 |
โข Threat: Impersonation
โข Target: GOV.UK users
โข Method: Credential Harvesting
โข Exfil: /Account/Login?ReturnUrl=%2F
โข Indicators: Domain mismatch, login form
โข Risk: High
The attacker sets up a fake login page that mimics the appearance of a legitimate service. The user enters their credentials, which are then captured by the attacker.
Pages with identical visual appearance (based on perceptual hash)
Found 4 other scans for this domain