Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18361746161412C4140078959B7E3674ED3B5C1124B134AAA07D298BAEBCEEBC95FB7CE |
|
CONTENT
ssdeep
|
48:d2+PZKB7tDgVZgfjcH6KeB/ACkEcDAVH6KeB/AgAVIKOrfhzqQO:Y08B7tRj5bx1N2bxRKOdRO |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cccc33b319cc66a6 |
|
VISUAL
aHash
|
180810181800ff00 |
|
VISUAL
dHash
|
301024b2320c2010 |
|
VISUAL
wHash
|
fcfcfcfc1c1c0000 |
• Threat: Disney+ login page phishing
• Target: Disney+ users
• Method: Imitates the Disney+ website to harvest credentials
• Exfil: Likely to an attacker-controlled server (details unknown)
• Indicators: Unofficial domain name (ddnsking.com), dynamic DNS
• Risk: HIGH - Credential theft risk.
Pages with identical visual appearance (based on perceptual hash)
Found 3 other scans for this domain