Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11092F27A664B553B0A9281D2D7223FD9B3D1544ED9890723E6ECC25D0BCBE5CEE0123E |
|
CONTENT
ssdeep
|
384:JTMLTMD7QTJTbTfTuTJTcTLFT1TSTfTCTgTJTzTDTmT0TCTrT3TqTxT+WFoZTkTd:JTMLTM3QTJTbTfTuTJTcThT1TSTfTCTQ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d64dada95252b895 |
|
VISUAL
aHash
|
fbf8d0f4f4fffec6 |
|
VISUAL
dHash
|
22f224acac1c0c2e |
|
VISUAL
wHash
|
fa708000f4f7fec2 |
|
VISUAL
colorHash
|
07e00000200 |
|
VISUAL
cropResistant
|
22f224acac1c0c2e,8398820b2343474d,a5438b9337265cb8 |
• Threat: Brand impersonation phishing
• Target: CLINIC+ customers in Japan
• Method: Impersonating CLINIC+ website to potentially steal data or distribute malware.
• Exfil: Unknown, but obfuscation suggests data exfiltration via an unknown API
• Indicators: Domain mismatch (stg2.clinicplus.health vs clinicplus.health), Obfuscated JavaScript.
• Risk: MEDIUM - Potential data theft or malware distribution
Found 1 other scan for this domain