Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17F41F061947DAE3752D787D661A2FF6E32D0C145CAC92B0847FC83AC4EE7CA2ED41145 |
|
CONTENT
ssdeep
|
48:0Lp6kwLFCMSPpR0OWp0ClrTWXV6QDKKbPBTpgeVlnEa:ywkw5CxuOWqC5TWXVljbtOMl1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dcdd8a2223267667 |
|
VISUAL
aHash
|
fcbc3c3c00000000 |
|
VISUAL
dHash
|
b1b0307050a8e1e1 |
|
VISUAL
wHash
|
fffefefc78000000 |
|
VISUAL
colorHash
|
000000001c0 |
|
VISUAL
cropResistant
|
a29aaa03123b1aa2,b1b0307050a8e1e1 |
• Threat: Phishing attack targeting MijnOverheid users.
• Target: Users of MijnOverheid in the Netherlands.
• Method: The phishing site attempts to trick users into believing it's the official MijnOverheid website.
• Exfil: Data exfiltration method unknown, likely credential harvesting.
• Indicators: Suspicious domain name, obfuscated JavaScript.
• Risk: HIGH - Potential for credential theft and unauthorized access to government services.
Pages with identical visual appearance (based on perceptual hash)