Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T160412299108E362B9623E1E0F60ABF07F1C684C7ED7ABE0094FE95D5C6D4F04E46B061 |
|
CONTENT
ssdeep
|
24:hnC/oLlie1ol3JAZcfWoy+97fef+O7b7ZIJKQqtIJBQffQksuQrkusrPC+ROtd1M:HAUoJJCcfWo7lO7BEmyRkprC+ROtXSZL |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8ce43399cc66b399 |
|
VISUAL
aHash
|
ffffdbdb18000000 |
|
VISUAL
dHash
|
96969696323004b1 |
|
VISUAL
wHash
|
fffffff318000000 |
|
VISUAL
colorHash
|
31000000e00 |
|
VISUAL
cropResistant
|
96969696323004b1 |
• Threat: Phishing
• Target: Spotify users
• Method: Credential harvesting
• Exfil: Unknown. Potentially to a database controlled by the attacker.
• Indicators: GitHub Pages hosting, Spotify branding, login form
• Risk: HIGH
The attacker is using a fake login page that mirrors the look of Spotify's real login page to trick users into entering their login credentials.
Pages with identical visual appearance (based on perceptual hash)
Found 4 other scans for this domain