Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E062D9A0A2545C27105782A4FBF09F28715DCAD6C7062A1851F1727AF9CFDA0DF357E8 |
|
CONTENT
ssdeep
|
192:dJSiSggMeM6sUYj0FAio6fO8xibYWIUo1cOJXZu8a4dvsJXSSJgEZ91AdPedPU:rSiSgg9JZYAFA36fO8agjJpUJb1AdGdc |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cccccccccccccc66 |
|
VISUAL
aHash
|
0000000000000000 |
|
VISUAL
dHash
|
1000000000000000 |
|
VISUAL
wHash
|
d8c0f0f0f0f0f0f0 |
• Threat: Brand impersonation phishing targeting users of the DANA payment system.
• Target: DANA users, potentially in Indonesia.
• Method: The site displays the DANA logo on a page hosted on a free hosting service.
• Exfil: Likely attempts to steal user credentials, though no forms are visible in the screenshot.
• Indicators: Use of free hosting (vercel.app), brand impersonation with logo.
• Risk: HIGH - Any information entered on this page could be stolen.
Pages with identical visual appearance (based on perceptual hash)