Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FD44C2785918AC2E0641848DE1CF3798B15FC24A8B0247ABB36B2D7F87E14B7757C663 |
|
CONTENT
ssdeep
|
1536:r3OOtc2B1U1g14yHJ4BHp2c3or502X2y2/HiHplFXWXHiuH31VxUgoC1wIUF:r3BOAGVup8c |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f08ad28b74a9de70 |
|
VISUAL
aHash
|
ffe7c3c3c3ffc2c0 |
|
VISUAL
dHash
|
59482a9696695c54 |
|
VISUAL
wHash
|
ff204343c3ffc0c0 |
|
VISUAL
colorHash
|
01007000000 |
|
VISUAL
cropResistant
|
59482a9696695c54,69e48d6b8b8ad232,0555a9a93763b9ac,44946c69b2967175,12326226995bc9c9,d9999ae56515d5d5,3979f8a8ade9a3b1,33ccac4cce9c8c63 |
โข Threat: Phishing
โข Target: PayPal users
โข Method: URL redirection and social engineering
โข Exfil: JavaScript obfuscation may indicate data exfiltration. The final URL after the redirect is unknown, so the location is also unknown.
โข Indicators: URL shortener, impersonation, javascript obfuscation, javascript form submission.
โข Risk: HIGH
The attacker aims to steal user credentials by redirecting them to a fake login page that mimics PayPal's legitimate site. Javascript obfuscation and form submission detection suggest the use of javascript to harvest and send the user's data to a malicious server.
The use of rebrand.ly is a method of hiding the malicious destination. The redirect is a form of social engineering.
mktconf.jsPages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain