Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CB73E932D2461103A05B85C8F1369B4D73528B4DCA138FB976FD17A9EACECF56762388 |
|
CONTENT
ssdeep
|
1536:TlGdBZA9uk7fayMALZdVuRw6NeWVv9ymKVZPVkgynKnnIjeeeeeaUnnETpeeeqUl:Wjk7RMAU9K7P/Ixk222I22222229aXm6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c02ecd329993ef4c |
|
VISUAL
aHash
|
fb00707e4c407c7f |
|
VISUAL
dHash
|
82aee6d8888ad8ba |
|
VISUAL
wHash
|
6b40727e42427e7e |
|
VISUAL
colorHash
|
06600030000 |
|
VISUAL
cropResistant
|
82aee6d8888ad8ba,8692939325651f23,8692939325651f23,499964f1330f2b22,8692939325651f23,8692939325651f23,4b4b7198d8d08c4d,3692db4bd21a2b2b,2565477747496b21,8692939325651f23,8692939325651f23 |
⢠Threat: Phishing
⢠Target: Shopee users
⢠Method: Impersonation through a blogspot site
⢠Exfil: Unknown, likely to steal credentials and financial data
⢠Indicators: Mismatched domain, brand logo use.
⢠Risk: High
The attackers are mimicking the Shopee brand to deceive users into providing their credentials or other sensitive information.
The attackers likely leverage social engineering tactics to create a sense of urgency or lure users into a false sense of security.
Pages with identical visual appearance (based on perceptual hash)