Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T135F251B09056AA3B02F392E0AB756B6FB3D5E2C8D943470516F8835D5FCBF94ED21092 |
|
CONTENT
ssdeep
|
384:cwJ7vZc+VW51az/CygUyD084mR8m9Q8lz/YBN5BnA8oA:cwpRc+Vu1aG1WQ8yVKLFoA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cf9a71218ec6ce8c |
|
VISUAL
aHash
|
00003c3c3c380000 |
|
VISUAL
dHash
|
4c9b616969631616 |
|
VISUAL
wHash
|
ff893d3c3cb8c0c0 |
|
VISUAL
colorHash
|
01000000e00 |
|
VISUAL
cropResistant
|
cc82155586664c46,4c9b616969631616 |
โข Threat: Phishing
โข Target: Bet365 users
โข Method: Impersonation via a look-alike website.
โข Exfil: User credentials (likely).
โข Indicators: Deceptive domain, obfuscated javascript, login form.
โข Risk: High
The attacker sets up a fake bet365 login page that collects user credentials (username and password) entered by unsuspecting victims. The form submits the data to a server controlled by the attacker.
Pages with identical visual appearance (based on perceptual hash)