Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15D5220B29485D93B5363C6E9B3B1A74BFB81C189C886014AE5F5D35C1FE3DB2EC0A215 |
|
CONTENT
ssdeep
|
96:j58HUZnoGyPFmGjZz/0/HrJSEmwh2FwGgjP2jHu+pafjztBkXejaE6SindVDJ9D7:j5kUCFMOuNSEGwt+UgjfDJep9ZTsrUJU |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
de7e61a1a19e9e80 |
|
VISUAL
aHash
|
80809c9cffffffff |
|
VISUAL
dHash
|
2822343003202024 |
|
VISUAL
wHash
|
80809c80cfcfcfc7 |
|
VISUAL
colorHash
|
07007000000 |
|
VISUAL
cropResistant
|
2822343003202024,0090f006e0e0e0e8 |
• Threat: Brand impersonation phishing using a free hosting service.
• Target: PayPal users are targeted.
• Method: The phishing page uses the PayPal logo and branding but is hosted on a blogspot domain, likely leading to a form for credential theft.
• Exfil: The form action points to the blogspot domain, suggesting data exfiltration through a custom script or similar method.
• Indicators: Free hosting, domain mismatch, brand impersonation, obfuscation detected.
• Risk: HIGH - Credential theft and potential account compromise.
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain