Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11D236397710816A9C3F3849944402990A2C7EB4FC9D19770C7780E7B2BE2A6167E9F7F |
|
CONTENT
ssdeep
|
768:DSzvXvglHUSW4P04P+4a/IeszHMuQZalcGC7cl0PdPLsAqY7/cz/:DSzvXYpU94M4W4a/IeyMuQZalcGC7clN |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
becd1ec1c1699632 |
|
VISUAL
aHash
|
ff9783c1efff8187 |
|
VISUAL
dHash
|
23272f0b1b332f2d |
|
VISUAL
wHash
|
ff918181cbfb8183 |
|
VISUAL
colorHash
|
06201000180 |
|
VISUAL
cropResistant
|
23272f0b1b332f2d,393139193933313d,01112561484b0b82,000124dac82c0300,bcf9830d2d2b491f,00114e889cd42100,c4e4557993969687,48e936081866e0bc,004823e0cce41340 |
• Threat: Website impersonating Stellantis for unknown purposes.
• Target: Stellantis customers, particularly those in Portuguese-speaking regions (Brazil, Portugal).
• Method: Displaying Stellantis branding on an unrelated domain to gain user trust.
• Exfil: Unknown, but potentially credential harvesting or malware distribution.
• Indicators: New domain, domain name mismatch, generic TLD, obfuscated javascript.
• Risk: HIGH - Brand impersonation with potential for malicious activity.
Pages with identical visual appearance (based on perceptual hash)