Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T167934BB1E501883D1F2F8AF5E41A66BED2429C0F79715CB0F5ADA3637683F644A17026 |
|
CONTENT
ssdeep
|
1536:LsnFw9QXF/qh7KhaBCHwtL7ZfT0ZNqchnFoYBaqq6lySAZHEit2lXMVDgzGryqya:LHCaqq6MSXajispDn3OqE+GnIWnIjiDY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b847c7383bc838c7 |
|
VISUAL
aHash
|
ffdfcf8d8fcfffff |
|
VISUAL
dHash
|
983b11191939960e |
|
VISUAL
wHash
|
7f898888888dc3ff |
|
VISUAL
colorHash
|
07401008000 |
|
VISUAL
cropResistant
|
983b11191939960e,2e672da53339590f |
โข Threat: Phishing
โข Target: Instagram users
โข Method: Impersonation of Instagram login page
โข Exfil: wss://edge-chat.instagram.com/chat (potential exfiltration of chat data, other JS exfil also possible)
โข Indicators: Domain mismatch, form present, JS obfuscation.
โข Risk: High
The site uses a visually similar login form to steal user credentials. When users enter their information, it is captured and sent to the attackers.
The site uses social engineering by mimicking a well-known brand's login page to trick users into entering their credentials.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain