Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T134B419A8F2B0640D43A7017A617F354473B6691EA56944287679CCEAB8E494C323FFFC |
|
CONTENT
ssdeep
|
6144:tRPyUDP0SutXn0HphBXi+ZcWW3Djwe6N8wXVB3q7lBIq5LtBo+8clJ:qOclSV0Bj5NlX |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f7227588dd88d998 |
|
VISUAL
aHash
|
e7e7e7e7fffffffe |
|
VISUAL
dHash
|
4d4d4d4d000c0000 |
|
VISUAL
wHash
|
00e7242481ff3d3c |
|
VISUAL
colorHash
|
0700000008b |
|
VISUAL
cropResistant
|
4d4d4d4d000c0000,40cccccc8ccd06e8 |
• Amenaza: Phishing
• Objetivo: Clientes de BT/EE
• Método: Suplantación de identidad a través de una actualización falsa
• Exfil: Desconocido, probablemente recopilación de credenciales o descarga de malware
• Indicadores: Alojamiento gratuito, logotipo de la marca, botón de llamada a la acción
• Riesgo: ALTO
The attacker likely wants to trick users into entering their BT or EE login credentials on a fake login page. The 'Click Here to Update' is a likely lead to a login form.
The 'update' button could lead to the download of malware to compromise the victim's device.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain