Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1441102604C3D566387A581E6F9A77E073A40C786D36A1F5084B4D3FD19C9E0DC9EB560 |
|
CONTENT
ssdeep
|
24:kHks1wspc8MT0C7OkCQqb5SpXQEiKn0SZxZjGx0JJ:C1zpxk4b5SpMY0c/jGWJJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b8cc9b7623336638 |
|
VISUAL
aHash
|
ffffdbc3c3c3c3c3 |
|
VISUAL
dHash
|
b0b2b28e96969696 |
|
VISUAL
wHash
|
7e5b5943c0c3c3c3 |
|
VISUAL
colorHash
|
07c00000000 |
|
VISUAL
cropResistant
|
a2948e80aa8ee0b2,b0b2b28e96969696 |
• Threat: Account suspension scam
• Target: Facebook users
• Method: Impersonation and a false claim of suspension
• Exfil: Unknown (likely credentials)
• Indicators: Suspicious domain, Facebook logo and branding, urgency.
• Risk: High
The attacker aims to steal user credentials by prompting them to log in or 'accept' terms. The ultimate goal is to get the user to enter their username and password, giving the attacker access to the account.
The phishing page creates a sense of urgency and distress by claiming the account has been suspended to get users to react without careful consideration.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain