Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T157A243329141AA730157E2D4B275976F7A8287C9CA4307A2A3F8975D9FCBCB9DE11308 |
|
CONTENT
ssdeep
|
384:oPpL85ad9ZlRqRERqRkdBAZEjrERfA8IDtRySeeLe8ieAPK+XLVRC:oPpAad9ZlEGE2dBAZEnERo8IDtISeeLN |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b2346dcdcf323232 |
|
VISUAL
aHash
|
c3c3c7ff7f6f7f7f |
|
VISUAL
dHash
|
869e9d4d79595959 |
|
VISUAL
wHash
|
c1c3c73c3c3c3c3c |
|
VISUAL
colorHash
|
06c00008000 |
|
VISUAL
cropResistant
|
869e9d4d79595959,0000000000000000,a369e994256d2c2d |
โข Threat: Phishing
โข Target: WhatsApp users
โข Method: Impersonation and promotional scam
โข Exfil: Potentially personal information and money
โข Indicators: Unrelated domain, requests a PIN, JavaScript obfuscation.
โข Risk: HIGH
The site uses social engineering by impersonating WhatsApp and offering a prize in an attempt to get users to enter their PIN or other sensitive information.
The site could potentially redirect the user to a malware download or execute malicious Javascript.
Pages with identical visual appearance (based on perceptual hash)
Found 3 other scans for this domain