Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A14186365010463755234DE5A0E5F706A2D3E24ECE9B24143BFC936947EED46CC5B3A4 |
|
CONTENT
ssdeep
|
48:nxCCG94X8idMC6BeWR2pe2VxLHrchTu9l1n:nzG9Q1B6JRSHrctm5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c4444461f1f3f376 |
|
VISUAL
aHash
|
000000ffffffffff |
|
VISUAL
dHash
|
94e0ac1016060000 |
|
VISUAL
wHash
|
000000c3c3ffffff |
• Threat: Facebook support impersonation phishing.
• Target: Facebook business account users.
• Method: Asks users to specify their issue to direct them into a phishing flow.
• Exfil: Unknown data exfiltration method at this stage.
• Indicators: Free hosting on pages.dev and a mismatching domain.
• Risk: HIGH - The site is impersonating a Facebook business support service to steal credentials.
Pages with identical visual appearance (based on perceptual hash)
Found 7 other scans for this domain