Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17732443161CA24BBC7594BA5FA10A75C45FB6B65C72A2D403B842C271CD2D81ADFA0BF |
|
CONTENT
ssdeep
|
96:nReE77ruHJJiPMscBpIoStdcZWmWGyGjcbfv9cYlYH+ehv4jl0fw3C:ReE7TMscTIoSsGGiv9oQB8l |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed6d6d9292929293 |
|
VISUAL
aHash
|
c3c3c3ffffffffff |
|
VISUAL
dHash
|
1696962912480000 |
|
VISUAL
wHash
|
c3c3c3dfff4e0000 |
|
VISUAL
colorHash
|
07000600010 |
|
VISUAL
cropResistant
|
1696962912480000,202c20a026080020 |
• Threat: Credential harvesting phishing targeting FedEx users
• Target: FedEx users
• Method: Fake login form on a non-FedEx domain to steal User ID and Password
• Exfil: Form actions point to '/landingpages/ac5c9c07-fe9d-4dc8-9780-8ff30d1206d7/j1cxrrh7-a99jcpazg1u1lchzsks0nyx0reukftnqsc'
• Indicators: Domain mismatch (internetservicetech.com vs fedex.com), login form, form submission via JavaScript
• Risk: HIGH - Real-time credential theft of FedEx accounts
Pages with identical visual appearance (based on perceptual hash)
Found 5 other scans for this domain