Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10E13973911519EBF1183D2F0F775AB6BF2A8C740C537DA56E2F9832A0BC6C45CE62264 |
|
CONTENT
ssdeep
|
768:GhRLaBLu1df1dthpslypdztZde6ASgjdQ:6IBLu1df1dth8y/ztZNidQ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d216e9e93c97b441 |
|
VISUAL
aHash
|
0000040400ffffff |
|
VISUAL
dHash
|
c6ccecaca53a0333 |
|
VISUAL
wHash
|
0004161450ffffff |
|
VISUAL
colorHash
|
1b203010000 |
|
VISUAL
cropResistant
|
808080c0c0808080,80a080b030b080a0,808080f070808080,a000a8ecaca88080,004a3594ce8a2180,c433330b33033333,d6ccccecececa4a3,1733713171793974 |
• Threat: Cryptocurrency investment scam
• Target: European investors
• Method: Fake registration form to harvest personal data.
• Exfil: validation/thankyou.php
• Indicators: New domain, domain name containing brand name, Javascript form submission, obfuscation (document.write, unicode_escape), form action validation/thankyou.php
• Risk: HIGH - Data theft, financial losses
Pages with identical visual appearance (based on perceptual hash)