Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15B5309F1209550BB4083CFCDDE33FE1AE2A39CBADF865B8251E9C6255996CD1CE05878 |
|
CONTENT
ssdeep
|
768:adHIeYKBpijoBmIyWD1qIiaU00o4zaLPPOYo0LNWON:adoFjZw19rr0oyeBION |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c35c7c166c176393 |
|
VISUAL
aHash
|
0000ffffffffffff |
|
VISUAL
dHash
|
3432c1e0d8c8c8c2 |
|
VISUAL
wHash
|
00007e7c7e7e7e70 |
|
VISUAL
colorHash
|
06002000c00 |
|
VISUAL
cropResistant
|
53c0c0c8c8c8c8c2,0c8e343334743635 |
• Threat: Phishing
• Target: Riyadh Region Municipality users
• Method: Impersonation via free hosting
• Exfil: ./DisplayLicenseDetails.aspx?DisplayMode=2&REQUEST_NUMBER=709DBC2831506513&REQUEST_YEAR=7A4246D8C90FED3F
• Indicators: Free hosting, brand logo
• Risk: Alto
The attacker creates a webpage that mimics the visual design of Riyadh Region Municipality in order to deceive users into providing sensitive information.
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain