Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1ED22B86190AA5D3F021782E8ABEA7F1367A7C746C6D20129C2FD97CD0FE9D50DA13528 |
|
CONTENT
ssdeep
|
192:jntKc1WzPnSMnRumGqnR4Y06GY4tc4t7es73o2hH:jtne//nRumGqnR4Y06GnV1ZzoeH |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b5338ac86cbc9c47 |
|
VISUAL
aHash
|
ff62020242ffffff |
|
VISUAL
dHash
|
c0ca4e5686a00600 |
|
VISUAL
wHash
|
7f00020000ffffff |
|
VISUAL
colorHash
|
07c00008000 |
|
VISUAL
cropResistant
|
c0ca4e5686a00600,23c5196380000212 |
• Amenaza: Phishing
• Objetivo: Usuarios de SwissPass
• Método: Recopilación de credenciales
• Exfil: princecorona/getlog.php
• Indicadores: Discordancia de dominio, acciones de formulario, suplantación de identidad
• Riesgo: ALTO
The website attempts to collect the user's SwissPass credentials (email and password) through a fake login form. Once entered, the information is likely sent to a malicious server controlled by the attackers.
Pages with identical visual appearance (based on perceptual hash)
Found 4 other scans for this domain