Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T144E30E72B5012D7F6787BE96E9267F01F2A18235F40B1794FBA5090A4FC2FF59226324 |
|
CONTENT
ssdeep
|
3072:r7FvGzGVBFuzasIEC6IX75RcOGDIdzkkLpMY9lKkNdjc58ktu4hw/2cj+hd2jEZ1:r7FvGzGVBFuzasIEC6IX75RcOGDIdzkD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cd56b34b2caa5325 |
|
VISUAL
aHash
|
fff8f8f0f0f8ffff |
|
VISUAL
dHash
|
2c50e02322d12a2b |
|
VISUAL
wHash
|
fff830101080dbdf |
|
VISUAL
colorHash
|
060010100c0 |
|
VISUAL
cropResistant
|
2c50e02322d12a2b,f1c77d5f7d477f7c,030d719f9f4e777f,010d619585614f7e,0109d52d65456561,e1071dc919599992 |
• Threat: Phishing
• Target: Capital One customers
• Method: Impersonation through a look-alike website on free hosting.
• Exfil: Unknown, likely credential harvesting
• Indicators: Cloudfront hosting, Capital One logo
• Risk: HIGH
The attackers are trying to steal Capital One login credentials. The page likely redirects to a form to collect this information.
The website uses the Capital One brand to trick users into believing it is legitimate.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain