Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12041753150148A13A98392C8A6E5A20B3686839AC74B4B046EF5937D7BD6E4BDD723D8 |
|
CONTENT
ssdeep
|
48:e4Xw9pcrliMth0OntMhuFU2gNdMcneIZHSbtpG:rXg7MdtMhN2JwEjG |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
99cc663399cc6666 |
|
VISUAL
aHash
|
0018181838181800 |
|
VISUAL
dHash
|
083032322a2a3008 |
|
VISUAL
wHash
|
0f0f1f1f28383030 |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
083032322a2a3008 |
• Threat: Phishing
• Target: Users of a webmail service
• Method: Credential Harvesting
• Exfil: Unknown, likely to a server controlled by attackers.
• Indicators: Unrelated domain, form with email/password.
• Risk: High
The site uses a login form on a domain not associated with any legitimate webmail provider to steal user credentials.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain