Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14263729361584A7F1D1B81D46214732F31A820CEFE4F56F9B8E5C2F8429FE91A5B29C3 |
|
CONTENT
ssdeep
|
1536:6bWNnpwL/JJd46kX9DPqm/shRD4/zUUe6VkVCK+QuZsvC9+oFSfrvGvrm7oWVSeb:Vgl4Ym//clb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b49c3ce7c7893238 |
|
VISUAL
aHash
|
ffc3dfffe7e7c381 |
|
VISUAL
dHash
|
2e37b7474d0d3733 |
|
VISUAL
wHash
|
8383c3e3e7e78381 |
|
VISUAL
colorHash
|
07000000e00 |
|
VISUAL
cropResistant
|
2e37b7474d0d3733 |
• Amenaza: Distribución de malware
• Objetivo: Usuarios que buscan versiones antiguas de GB WhatsApp
• Método: Disfrazado de sitio de descarga legítimo.
• Exfil: Desconocido, probablemente APK malicioso.
• Indicadores: Dominio no oficial, ofrece descarga de APK.
• Riesgo: Alto
The site uses the guise of providing old versions of GB WhatsApp to trick users into downloading a potentially malicious APK file. This file could contain malware that infects the user's device and steals their data.
The site's visual design aims to imitate the GB WhatsApp brand, making it more likely for users to trust the download link.
Found 7 other scans for this domain