Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10F41A7B6604569B75287D1F1BB70A71FBB8282C9DF63220257F9C3AC5BD6C58DE05050 |
|
CONTENT
ssdeep
|
24:n/CoAfDflGDeHhd/evMwvg4A0VmBcTitErsFpMuHNVNEIQrZAwpZA4VZSHaNHN9s:nmr9AeHhIA0Vscgu+pPtvGow6Kyt1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f3c9cc2699662699 |
|
VISUAL
aHash
|
ffffe7effee6e4fc |
|
VISUAL
dHash
|
28280c08284c4c30 |
|
VISUAL
wHash
|
f6fae0e8e0e0e0d8 |
|
VISUAL
colorHash
|
070010001c0 |
|
VISUAL
cropResistant
|
28280c08284c4c30 |
β’ Threat: Credential Harvesting
β’ Target: Users of potential document access services
β’ Method: Phishing email verification
β’ Exfil: https://nextjs.gegava.biz.pl/m33vS@OBe/#
β’ Indicators: Unrelated domain, suspicious form action, generic branding
β’ Risk: High
The attacker is attempting to steal user credentials (email address) by mimicking a document access login page.
The suspicious form action suggests that submitted credentials might be sent to a phishing URL for exfiltration.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain