Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FB6175F3C2008C1F5711C19449A2BE5A126681CBCA5C2E2262F452EF19D9EF4D9733A6 |
|
CONTENT
ssdeep
|
48:nbV5bfdspa3SJgBHor9iQoI2wCiPDT4cAaN586ApBa:nhncJ+IGBLaNKK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
912d7885f45a2eda |
|
VISUAL
aHash
|
434300007e7efcc3 |
|
VISUAL
dHash
|
969679968aaae98a |
|
VISUAL
wHash
|
43430000fffffcc3 |
|
VISUAL
colorHash
|
090000001c0 |
|
VISUAL
cropResistant
|
d4f4e9b3b4ed7301,3999d69696d6e626,96963269664eb9a9,9b153728287575b0,232ce2d296725a9a,58cac66e46c48566,9696326126a6a4a4,243454ac26d2ed6d,929293952664e452,2929a5b786965656,3a3ab533555525a4,cba333a0a0b136b8,969679968aaae98a |
• Threat: Phishing
• Target: BRI customers
• Method: Deception, offering rewards.
• Exfil: Unknown, likely to obtain personal information
• Indicators: Recent domain, domain unrelated to the brand, reward offer.
• Risk: Moderate
The attacker is impersonating BRI to lure users into providing information.
Offering a reward, prize or coupon to entice users to engage with the fake site.
Pages with identical visual appearance (based on perceptual hash)