Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E504ABF053D00D5A17B2B8D2DE23FE5A1FA2C6B1F91B2609E398566C5CE3EF0E942154 |
|
CONTENT
ssdeep
|
1536:Q/qXecbH0C/YJMQYEHBXOgit7iZePEcPXSWxcfy+bH2+96LMQmYHVxggit7wZkP8:/XB4G0zTw6+3J6+G+HQqaG7h |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b131c69b9bce6431 |
|
VISUAL
aHash
|
ffc3c3dfcfd3f3ff |
|
VISUAL
dHash
|
609696131b17279e |
|
VISUAL
wHash
|
ffc381898981dbc3 |
|
VISUAL
colorHash
|
07001000180 |
|
VISUAL
cropResistant
|
609696131b17279e,01a209b606b0bc83 |
โข Threat: Phishing
โข Target: Unspecified users
โข Method: Imitation of a payment portal
โข Exfil: https://translate.googleapis.com/translate_voting?client=te_lib, step1.php
โข Indicators: Obfuscation, Javascript Form, forms detected
โข Risk: HIGH
The attacker aims to steal user credentials (like Israeli ID numbers, license plate numbers) by creating a fake login form that mimics a legitimate service.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain