Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C902866090BA6D3F520781EDA7A52F12A6A7C345CBD34226C2FED78C0FE9C51DB02554 |
|
CONTENT
ssdeep
|
192:nnG6Zmzd3LnRumGqnR4Y06GY4T4s3ogQF:nGcOd3LnRumGqnR4Y06Gn8+oPF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cccc333366cccc99 |
|
VISUAL
aHash
|
1818181800000000 |
|
VISUAL
dHash
|
3032b23210000000 |
|
VISUAL
wHash
|
1c1c1c1c1c1c0c0c |
|
VISUAL
colorHash
|
00000038000 |
|
VISUAL
cropResistant
|
8080808080808080,808080c0c0808080,3032b23210000000 |
โข Threat: Credential Phishing
โข Target: SwissPass users
โข Method: Impersonation with a fake login form
โข Exfil: s/1.php
โข Indicators: Domain mismatch, obfuscated javascript, form data.
โข Risk: HIGH
The attacker aims to steal SwissPass login credentials by mimicking the official login page and capturing user input.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain