Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T143D46CE637A5942746D1818AA079471363397E0E5809C12CFE3EFDDB2A9CD85B07BB70 |
|
CONTENT
ssdeep
|
6144:piXJZOc8dXPc5HFAh48tbL+K8ufR1JOfCCJ55EofIWeRMmlc95OY79++2naoHI:G8Fcp8t+8fQfCCJP97CHI |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
99cc663399cccc99 |
|
VISUAL
aHash
|
0000181818180000 |
|
VISUAL
dHash
|
304cb2b2b2b24c30 |
|
VISUAL
wHash
|
00001818d8d8e4fc |
|
VISUAL
colorHash
|
00000038000 |
|
VISUAL
cropResistant
|
8a8ca2aaeaa833b2,304cb2b2b2b24c30 |
⢠Threat: Phishing
⢠Target: Shopee users
⢠Method: Impersonation and credential harvesting.
⢠Exfil: Unknown, but likely through a Supabase endpoint.
⢠Indicators: Mismatched domain, requests for sensitive information.
⢠Risk: High
The attacker is trying to collect personal information in order to steal the user credentials, that can then be used for identity theft.
The attacker leverages the brand image of Shopee to gain the victim's trust, making them provide the necessary information.
Pages with identical visual appearance (based on perceptual hash)