Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T166516365C108DD2B9164C0D0E571A32C96C9828993130B9893EC463C26EB9AADC6FEC8 |
|
CONTENT
ssdeep
|
48:ZDfE+LQ8mHDQeMt5MSjWAUf1sHcKtub8CXSL5fh6qLv:Zvt5Mvq8KtuXoNhhv |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a20f993726dd7322 |
|
VISUAL
aHash
|
071f271f273f7f7f |
|
VISUAL
dHash
|
59b2ceb1ad529495 |
|
VISUAL
wHash
|
0307071f071f3f1f |
|
VISUAL
colorHash
|
07201018040 |
|
VISUAL
cropResistant
|
59b2ceb1ad529495 |
• Threat: Phishing/Unauthorized Access Portal
• Target: General Users
• Method: Password-gated landing page using obfuscated JS
• Exfil: Likely credentials or session tokens
• Indicators: Obfuscated JS code, unrelated domain name
• Risk: High
Uses a fake password wall to harvest entries from users attempting to access 'secret' content.
Uses code masking to prevent automated analysis tools from detecting the final destination or exfiltration point.