Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DF6308BC42521A8EB03BC5C7BA61BB2CC131538ADF770DD9F6E63022D7DD86901A55B8 |
|
CONTENT
ssdeep
|
768:MRJnTAR3scHoRdXXFTo0g4ZrS/nTAR3s/yyCbLjQWBf4H4QVgU:MrTNGudnmMm/TNYkWBWn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cb25359e39bc2613 |
|
VISUAL
aHash
|
032020787c3c3c08 |
|
VISUAL
dHash
|
3a4ac9f2e9e9783a |
|
VISUAL
wHash
|
03206878fcfebe1c |
|
VISUAL
colorHash
|
31000000000 |
|
VISUAL
cropResistant
|
cb8b2b2b2b2babcd,9811333a9cc4569b,f25654542c5a928a,f08094373380a2f0,3a4ac9f2e9e9783a |
• Threat: Credential Harvesting / Phishing
• Target: General users
• Method: Obfuscated JS form submission
• Exfil: Unknown backend
• Indicators: Obfuscation, generic high-tech branding
• Risk: High
The site uses obfuscated JavaScript to capture input data when users interact with CTA buttons or forms.
Uses vague, pseudo-professional terminology to build false trust.