Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17621EEB0408125FB45829A808FB6F3A94794C2D9ED8356009EDDA3ED4DCEBA9CD03351 |
|
CONTENT
ssdeep
|
24:haSbOsaDVK3DYButxFEFuiHFkfo2F5Ps/xFEFuiHF42F5msBoPLa:Hbdma0CEge0l+EgeXAsl |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9999666666cc9966 |
|
VISUAL
aHash
|
183c3c3c00000000 |
|
VISUAL
dHash
|
f3b3b2b2d7dff7df |
|
VISUAL
wHash
|
1c3c3c3d1b070f1f |
|
VISUAL
colorHash
|
003c0000000 |
|
VISUAL
cropResistant
|
f3b3b2b2d7dff7df |
• Threat: Phishing
• Target: Unspecified (gambling/casino enthusiasts)
• Method: Deception, enticing users with bonus offers on an untrusted domain.
• Exfil: Unknown (likely login credentials, financial information).
• Indicators: Unrelated domain, bonus offers, Chinese text, JavaScript obfuscation.
• Risk: HIGH
The site likely lures users with offers and bonuses to obtain their login credentials and possibly financial information. The links provided may redirect to a login form on the attacker's server.
The site could lead to downloading malicious payloads.
Pages with identical visual appearance (based on perceptual hash)