Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19C7267B260049C3F81A383DDE671333E52AA538ACA4F131976EA475E89D3F41EC3B525 |
|
CONTENT
ssdeep
|
192:CuTWIIoic7epn62kn7djxcpIqVtnw2XuD+T3QvlMMGpWBTPpEmBMFgBUPamRdq:LCIIonex4jxUO2+6XWPZBQgBUPfq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c3833c381ec7c3e3 |
|
VISUAL
aHash
|
0000707c70706000 |
|
VISUAL
dHash
|
9c5ac4c0c8c0c000 |
|
VISUAL
wHash
|
00077f7ffef0f000 |
|
VISUAL
colorHash
|
38000038000 |
|
VISUAL
cropResistant
|
9c5ac4c0c8c0c000 |
• Threat: Phishing/Fraudulent Landing Page
• Target: Unspecified
• Method: Impersonation of a tech corporate entity
• Exfil: JavaScript-based submission
• Indicators: Vague metrics, recent domain, obfuscated JS
• Risk: High
Uses a professional-looking template to build fake authority, likely leading to a drainer or phishing form later.
Uses unescape to hide scripts that might track visitors or initiate malicious redirects.