Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13E63307292542837617B79D6F064672AD2D7C70FCA8346E1A2F8D39A0FD6CE1E86340D |
|
CONTENT
ssdeep
|
1536:zeRXWnRrXhZePZsglETgM5gFzMgJIgM9gtQgaegLUgpZg7RgN8gNGgNGgd2ghug0:6RXWlh9tEzrWeAbDQ0zl1JcCs56grtlx |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b0866dd3d98c9c39 |
|
VISUAL
aHash
|
2424dfffc7e7c3c3 |
|
VISUAL
dHash
|
c8cc36301e0e1712 |
|
VISUAL
wHash
|
0000d7ffc7c7c3c3 |
|
VISUAL
colorHash
|
07001000042 |
|
VISUAL
cropResistant
|
c8cc36301e0e1712,8e8e179789876626,695d2b2b654d2333,4119694c930f094d,63473d752d353d0f,8b938531456d6561,4d03767d54565c78 |
โข Threat: Phishing
โข Target: Unknown
โข Method: JavaScript obfuscation and form submission
โข Exfil: /search
โข Indicators: Obfuscation detected, suspicious form actions
โข Risk: High
The site uses obfuscated JavaScript to hide malicious actions.
Collects user credentials through a form.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain