Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1633102F1916878AFB1A2D660B3E5FB8922819342D3100844F3D8A5BF55DED6489B36EC |
|
CONTENT
ssdeep
|
24:QTIspwLq3DOqyqu+FfTrGDhtfqaxOJWZFulcErGqY2N9uElmxOJWZFulcIwwjOBF:opmqyqLOtJqaY2F2HxMYuPB6m |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc3cc3c1c03e3763 |
|
VISUAL
aHash
|
179f8707efffffff |
|
VISUAL
dHash
|
26363e3696000000 |
|
VISUAL
wHash
|
0303030300fcfcfc |
• Threat: Credential harvesting phishing targeting Made-in-China.com users.
• Target: Users of Made-in-China.com platform.
• Method: Presents a fake login form to steal email and password.
• Exfil: Data exfiltration destination is unknown (likely a server controlled by the attacker).
• Indicators: Domain mismatch (docbolotov.ru vs. made-in-china.com).
• Risk: HIGH - Immediate risk of credential theft.
Pages with identical visual appearance (based on perceptual hash)