Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19093BB23426975274437C2C1347A5B3BD1A6D98FFEE70A010EECCBFA6AF9C90741A519 |
|
CONTENT
ssdeep
|
768:2opTctpR4nXF6YjOpSpFlTC6rr7qgCIpyhXutGAp0AA2q:2opYtpR4nXBKpSpFl26vPC/putGfAjq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c365bc3bc1e1e21c |
|
VISUAL
aHash
|
f88870700804e8fc |
|
VISUAL
dHash
|
c239c7c3524d4bf0 |
|
VISUAL
wHash
|
fe9870700e05f8fc |
|
VISUAL
colorHash
|
30400038000 |
|
VISUAL
cropResistant
|
c239c7c3524d4bf0 |
โข Threat: Phishing
โข Target: Unsuspecting users
โข Method: Credential harvesting
โข Exfil: https://thezyberlichbeam-ai.org/assets/submit.php
โข Indicators: Suspicious domain, form, obfuscation.
โข Risk: High
The website uses a form to collect personal information (email, name) which could be used for account takeover or phishing attacks.
Data collected through the form is sent to a PHP file on the same domain, which suggests a backend script is collecting the submitted information.