Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T156834631D367181390AFD2D4B171474923928789CA134BB967FD63BAFACDCB53623298 |
|
CONTENT
ssdeep
|
1536:e11DXgyeeMXehXexiPUgOq61e61tICbe9E8eeYdqNirQCcrW+SfbMP3+0fHonzHX:V2FPUgOq6NL5ukJRk222I2222222dsXu |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b2cdc73930938ccd |
|
VISUAL
aHash
|
fff17f46c1c147c5 |
|
VISUAL
dHash
|
c0e7e48c8d8d8c8d |
|
VISUAL
wHash
|
fff17e4645404645 |
|
VISUAL
colorHash
|
02200038000 |
|
VISUAL
cropResistant
|
c0e7e48c8d8d8c8d,9192b2b0a9a0a2f2,01d924f035172b2b,d7693248cccc452c,676d4f7747597b23,9793d6c469239171,4753713c30504061 |
โข Threat: Phishing
โข Target: Shopee users
โข Method: Impersonation via giveaway
โข Exfil: Likely steals personal information if the user interacts with the site. The presence of obfuscated javascript makes the actual purpose unclear.
โข Indicators: Mismatched domain, giveaway theme, obfuscation.
โข Risk: High
The attackers are mimicking the appearance of Shopee to deceive users into providing personal information or clicking malicious links.
The site uses a giveaway to entice users into interacting with the fake site.
Pages with identical visual appearance (based on perceptual hash)