Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T191213E21984C6C736643D2C0AA93FB077AC28585CF5B170426F283ED36E7E6ACC19142 |
|
CONTENT
ssdeep
|
24:n/CH4LuDfqmHJDZfk7zHagZDN/EwNEN9rYT7ADjioJDy0JDwNwm:nfCSqZYXpN/LaHUT7mpy0NwNwm |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cccc333399cc6666 |
|
VISUAL
aHash
|
0018181818180000 |
|
VISUAL
dHash
|
081034b232301000 |
|
VISUAL
wHash
|
3c3c3c3c1c1c1c0c |
|
VISUAL
colorHash
|
38000000e00 |
|
VISUAL
cropResistant
|
081034b232301000 |
• Threat: Credential harvesting phishing kit
• Target: Spotify users worldwide
• Method: Fake login form stealing email and password
• Exfil: Data sent to custom API (include/send_log.php)
• Indicators: Mismatched domain, suspicious form action, JavaScript form submission
• Risk: HIGH - Immediate credential theft
Pages with identical visual appearance (based on perceptual hash)