Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19A41632250195D2B13C2D0D0A7F0B60FA7938743C6074F0686F487CEAEC8DB8CD992E9 |
|
CONTENT
ssdeep
|
48:9y2Dg6G/QNHlZKNWomvqJvzj+GaDXIMpl:xGClbvqJbiDh |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b33333dccccc464c |
|
VISUAL
aHash
|
24e7e7ffffffffff |
|
VISUAL
dHash
|
084c0c0010080000 |
|
VISUAL
wHash
|
0004e0f83f3f0f0f |
|
VISUAL
colorHash
|
000000001c0 |
|
VISUAL
cropResistant
|
084c0c0010080000,0161457131414101 |
โข Threat: Phishing
โข Target: Unspecified users
โข Method: Impersonation and credential harvesting.
โข Exfil: https://patrona.matesdaddy.com/santacruz.php
โข Indicators: Free hosting, form submission, obfuscation.
โข Risk: High
The attacker attempts to steal user credentials by creating a fake login form on a free hosting service. Users are tricked into entering their login details, which are then sent to a server controlled by the attacker.
JavaScript code has been obfuscated to hide its true functionality and prevent easy analysis of the phishing attack.
Found 2 other scans for this domain