Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EC91EEB090927A3B01D383D2EF79AB9AB3D442D0FA47570502F4D3498AC9F1EED61C60 |
|
CONTENT
ssdeep
|
96:T6NOzBJoFDOG2jV/3C5QdeQiD/jmdRqUS/JdhLLPLk+:WYBJoDGghD/JdhLjw+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8e19394edcd14e4e |
|
VISUAL
aHash
|
000b01ffb430ffff |
|
VISUAL
dHash
|
72dbddbc65656515 |
|
VISUAL
wHash
|
000b01ff3030ffff |
|
VISUAL
colorHash
|
07207000000 |
|
VISUAL
cropResistant
|
828262eaeae28282,dbdf99a465656555,62db1adbdbef9dde,d9e6766663697926,4c9736666d595932,6c5e5e5e7e7c7c78,7d6b5fe7e74f4dcc,3b0d040404149594,b3e7676e6e7e3e2d |
• Threat: Phishing
• Target: Amazon users
• Method: Impersonation through a look-alike website
• Exfil: Unspecified, likely credentials or payment details if the site was further developed.
• Indicators: Vercel hosting, Amazon logo.
• Risk: High
The attacker likely intends to trick users into entering their Amazon login credentials on a fake login page that mimics the real Amazon site. This allows the attacker to steal the victim's account.
The site could redirect to a more sophisticated phishing page that also requests additional personal or financial information.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain