Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18931363653088C3FF111C398D7B0B279666B028BDB462260C6EE47AD9175D86DC3B1CC |
|
CONTENT
ssdeep
|
48:k5NmTNMcOu5aJghl2BE78ZScXJwyaviI4:k1uwCqa8RXv |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c9c833b6cccc3687 |
|
VISUAL
aHash
|
f8f8f8d818030707 |
|
VISUAL
dHash
|
01000032321e5f9e |
|
VISUAL
wHash
|
fcf8f8f818070707 |
|
VISUAL
colorHash
|
38007000000 |
|
VISUAL
cropResistant
|
01000032321e5f9e |
• Amenaza: Impersonación
• Objetivo: Usuarios no especificados
• Método: Mostrar un mensaje de acceso restringido genérico para robar credenciales.
• Exfil: Desconocido
• Indicadores: Texto en francés, dirección IP, edad de dominio sospechosa
• Riesgo: ALTO
The attacker attempts to steal credentials by displaying a misleading message to trick the user into thinking something is wrong.
Collect the user's IP address.
Pages with identical visual appearance (based on perceptual hash)
Found 5 other scans for this domain