Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12D453A0832523611C1A79097D93F2585A239D04BA40A84D87F3C8BF71FA9F99D67BF36 |
|
CONTENT
ssdeep
|
12288:zuvtR8k28y7WJeXM6vxg24QsKF20hNoH9Q/SYsBHk92jOTFYs6+e5/:zuvtRry7hXF6H9ySYsO92jOTF/6R5/ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
868692f1f1f1a68e |
|
VISUAL
aHash
|
ff34306000000000 |
|
VISUAL
dHash
|
5c6565d8b0103838 |
|
VISUAL
wHash
|
ff1410ffcc8c848c |
|
VISUAL
colorHash
|
0f000000e00 |
|
VISUAL
cropResistant
|
5c6565d8b0103838 |
• Threat: Credential harvesting phishing
• Target: bet365 users
• Method: Fake login form stealing username and password
• Exfil: Likely to a malicious server
• Indicators: Domain mismatch, suspicious domain name
• Risk: HIGH - Immediate credential theft
Pages with identical visual appearance (based on perceptual hash)