Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C55161B245000C2B45A7C5D07BEFB71B41D5C686C2894A26C5FC4BCD0AEED92D973399 |
|
CONTENT
ssdeep
|
48:wMORvLcr+5Xmuv15dplrmklmUeqfV6SJSJS5Hh++1XbRxg8AOZdvh:gvLc6BJlrmklNTV6SJSJS571XdG8nZdZ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d972d89d278d2607 |
|
VISUAL
aHash
|
fec8000000181818 |
|
VISUAL
dHash
|
181893524e32b2b2 |
|
VISUAL
wHash
|
fffffb2000383818 |
|
VISUAL
colorHash
|
314000c0000 |
|
VISUAL
cropResistant
|
1313300c0d314d4c,181893524e32b2b2 |
• Threat: Potential data harvesting.
• Target: Users of toll roads in Brazil or Portugal.
• Method: Collecting license plate data via a form.
• Exfil: Data sent via JavaScript form submission (likely to a custom API).
• Indicators: Recent domain, form submission detected.
• Risk: LOW - Potential data harvesting if malicious but appears to be a legitimate service.
Pages with identical visual appearance (based on perceptual hash)