Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1897241209178FD7306F39BC16B751AE3F3D18186CB130A5091F887AEE799C94CE5E2A5 |
|
CONTENT
ssdeep
|
384:JQWWxAvHWu0gQ1EhkKuxSemG/Bs62b0OWKvmzf9zCFrDr+e0rshrjzorS5:JQlxAvHWJgQ1EhFuxSemG/Bs600OWem2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9616bb3b1cb97910 |
|
VISUAL
aHash
|
0e06061614ffffff |
|
VISUAL
dHash
|
6cecece464950c0e |
|
VISUAL
wHash
|
0c06041404ffffff |
|
VISUAL
colorHash
|
16600000001 |
|
VISUAL
cropResistant
|
fddddd776779fb38,d3939392d2ccf8b9,9e0c0e00000c0e0e,7cecececec646471 |
โข Threat: Phishing
โข Target: TikTok users
โข Method: Impersonation and data harvesting
โข Exfil: Unknown, likely to a server controlled by attackers
โข Indicators: Domain mismatch, obfuscated JavaScript, multiple forms.
โข Risk: High
The site attempts to steal user credentials by creating a fake login/signup page. The forms detected suggest this intent.
Hidden javascript could potentially download or redirect to further malicious content.
Pages with identical visual appearance (based on perceptual hash)