Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17C02A871C4089D77A002D7A8EAF9BB662363975CCA871748D6F4D3983FCBCA4DC51588 |
|
CONTENT
ssdeep
|
192:WNjLJ0rKbLDBsfcN0PHDX9n+Po66pbcJQtQeShdKsb92:oNygsfrf1+PgpoJeQemdKsx2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9999666666333333 |
|
VISUAL
aHash
|
1818181818000000 |
|
VISUAL
dHash
|
b2b2b2b2b24c3000 |
|
VISUAL
wHash
|
3f3f3f3f1c0c0000 |
|
VISUAL
colorHash
|
07001000031 |
|
VISUAL
cropResistant
|
8c4d0fe896964db2,b2b2b2b2b24c3000 |
โข Threat: Phishing
โข Target: BankID users
โข Method: Credential Harvesting
โข Exfil: ./snd/step-three.php
โข Indicators: Domain mismatch, form requesting password
โข Risk: High
The attack involves a fake BankID login page designed to steal the user's password.
Pages with identical visual appearance (based on perceptual hash)