Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14C818327F51CA46E4BC084F4A830B6ECD60F54CEE441CECDABE0C4AD56ED6D582F2A56 |
|
CONTENT
ssdeep
|
96:SsRHIH6TP79ylw/FzxGcU2HxGcvtxGc1xGchxGcci5/IIFGmON1r:7RHIH6TPAwtzxLUixLvtxL1xLhxLcBQ4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a9863b3c248fd8f2 |
|
VISUAL
aHash
|
03036b03030b0303 |
|
VISUAL
dHash
|
2fcbabd79793530b |
|
VISUAL
wHash
|
070f7b73434b8b83 |
|
VISUAL
colorHash
|
31000400030 |
|
VISUAL
cropResistant
|
74f474f474747473,e4f0b1b4c968b0e0,c4a2942b2bada2c2,32e594e98b896816 |
• Threat: Phishing
• Target: Ndax users
• Method: Impersonation via free hosting.
• Exfil: Potentially through forms (if present).
• Indicators: Free hosting, brand logo.
• Risk: High
The attackers are likely trying to trick users into entering their login credentials into a fake form that looks like Ndax. Once the credentials are submitted, the attackers will have access to the user's account.
Pages with identical visual appearance (based on perceptual hash)