Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T154321F30124EADF206F3EE7FFEA5DB99D0638646C3150D05626C2A6BA9D3D4071B84E9 |
|
CONTENT
ssdeep
|
192:ReE7sxQyE8/XJTFcFcBcmr2ccGS1Giv9RepI2snL36hAefFc4DORoidGD:ReasxQy7/JTFc6Bcmr21GSoiv9RepI2R |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed6d6d9292929293 |
|
VISUAL
aHash
|
c3c3c3ffffffffff |
|
VISUAL
dHash
|
1696962912480000 |
|
VISUAL
wHash
|
c3c3c3dfff4e0000 |
|
VISUAL
colorHash
|
07000600010 |
|
VISUAL
cropResistant
|
1696962912480000,202c20a026080020 |
• Amenaza: Phishing para robo de credenciales
• Objetivo: Clientes de FedEx
• Método: Formulario de inicio de sesión falso que roba el ID de usuario y la contraseña
• Exfil: Datos enviados a destino desconocido (acción del formulario: /landingpages/ac5c9c07-fe9d-4dc8-9780-8ff30d1206d7/pmxtnezlw_bpcs9y5rfb_yhvkottbsmymih4vssuhzk)
• Indicadores: Dominio no coincide, envío de formularios JavaScript
• Riesgo: ALTO - Robo inmediato de credenciales
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain