Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11952977180584C3B416386C4B6F5671A3056C31EDA831B056BF8C7AD2EF7DA1ED1E26B |
|
CONTENT
ssdeep
|
192:h80nXC6bAMw5zRCRE6TY4sJe4ZuzUWgvUkJ8TZu8k2jjNqsGqq/+j:G0ny2jcdrq8ZuzevU9ZuYqjr2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b3d84ce662f258d8 |
|
VISUAL
aHash
|
7ee7ffe7e7e7e700 |
|
VISUAL
dHash
|
840c160d0c4d0c04 |
|
VISUAL
wHash
|
00e7c3c3e7e7e700 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
840c160d0c4d0c04 |
• Threat: Credential harvesting phishing kit targeting Network Solutions users.
• Target: Network Solutions email users.
• Method: The attack uses a fake webmail login form to steal email credentials.
• Exfil: Data is likely exfiltrated to a Telegram bot (token 7621126660:AAFWo5oVsmOje-C87JFFzz_ziRsJCVTaLeY).
• Indicators: The domain demo.printincbelize.com does not match Network Solutions and is an old domain used for phishing, the page has obfuscated JavaScript, and exfiltration to Telegram is suspected.
• Risk: HIGH - Immediate credential theft is possible.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain