Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A081643170249C26D202CDE8A2D1DB26A2878351C7866D24F5F08A5D7BDBCD0D669DBE |
|
CONTENT
ssdeep
|
48:ncKthPyvRl+xJXEKYrHJKJVaTzvJqL/aPYJHgZzo6hCxp5GHp6n15kEuBlI+0:n9wy6Ho2TEjHang5GHp6n15kEuBlIR |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
889db63217983377 |
|
VISUAL
aHash
|
1c1c18181841c1c1 |
|
VISUAL
dHash
|
b0b0b2b2b38f8707 |
|
VISUAL
wHash
|
1e1c185879e3e3e3 |
|
VISUAL
colorHash
|
00000000006 |
|
VISUAL
cropResistant
|
f8b1b989e9816919,fefcfcf8f0f0e0c0,28b0d6dedeefffff,b0b0b2b2b38f8707 |
• Amenaza: Ataque de phishing para robo de credenciales
• Objetivo: Clientes de Virgin Media en el Reino Unido
• Método: Formulario de inicio de sesión falso que roba correo electrónico y contraseña
• Exfil: Probablemente una API personalizada (no especificada)
• Indicators: Desajuste de dominio, formulario de inicio de sesión, suplantación de marca
• Riesgo: ALTO - Robo de credenciales en tiempo real
Pages with identical visual appearance (based on perceptual hash)
Found 6 other scans for this domain