Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D2C2A4305186F8371987B3D0E376A74AB3959788E6034B0A63FDC75D2FCAD44EC2A661 |
|
CONTENT
ssdeep
|
384:TkFwBdh7lImfWbKI6E8WZ7WeI1eIyKTzpi6mm5GZVWs7mBCqIOqZjlOdqz:TkFw/9Ba9I0Iv1EX72VQYqz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d234ebad14969569 |
|
VISUAL
aHash
|
0000040600fffdfd |
|
VISUAL
dHash
|
96df9cbc9c332321 |
|
VISUAL
wHash
|
0000060e0effffff |
|
VISUAL
colorHash
|
1b002000180 |
|
VISUAL
cropResistant
|
a080c068688080a2,a080c0b030a08092,a080a81a1aa080a2,0800189ada280008,0006686969699620,1b002b2329210103,923fde9c9cac9c98,4cb0f06060e02129 |
• Amenaza: Phishing
• Objetivo: Usuarios de EvoVerdex (víctimas potenciales)
• Método: Impersonación y un formulario de registro falso.
• Exfil: validation/thankyou.php.
• Indicadores: Edad del dominio, ofuscación, formulario de registro.
• Riesgo: Alto
The attacker aims to steal user credentials by creating a fake login/signup page that mimics the legitimate website. When users enter their information, it's sent to the attacker.
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain