Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14831607380021C1A5713A1919F35B31EA3BB4689C7E31E05B4D9527AA2EADF4842F58E |
|
CONTENT
ssdeep
|
24:k1Tn2ZJnT4pGY9PhD8hbxrniP1l/sFZSMz2dJFfT2iHTaQqnjtTZh+VH9ESoX:+nAJT4D/DibFnitl/AZLC9lQn5VhoHoX |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fa7e7a7e72c48080 |
|
VISUAL
aHash
|
0000ffffffffffff |
|
VISUAL
dHash
|
0111000000000008 |
|
VISUAL
wHash
|
000000fff0f0fce4 |
|
VISUAL
colorHash
|
06000038400 |
|
VISUAL
cropResistant
|
0111000000000008,0000000000000000 |
• Threat: Account status notification
• Target: QR.io users with deactivated QR codes
• Method: Informs user about QR code deactivation
• Exfil: No data exfiltration detected
• Indicators: Official domain qr.fm
• Risk: LOW - Informational message about account status
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain