Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1847343BFC0420DEF1343DBA460B7FFE8928AD70AF9724490E2D856692D87D3F9142656 |
|
CONTENT
ssdeep
|
1536:MjtFvae8gfvPXjPNv9b0oC11fTqH+H0ugZUa8S/H:McGagqa/f |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d80337f8dd880df4 |
|
VISUAL
aHash
|
18181898d8d8d8d8 |
|
VISUAL
dHash
|
302872b232b13232 |
|
VISUAL
wHash
|
181838fcfcdcd8d8 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
302872b232b13232 |
• Amenaza: Phishing
• Objetivo: Clientes de Shaw
• Método: Suplantación de identidad a través de Linktree
• Exfil: Potencialmente credenciales de usuario, redirección a sitio malicioso
• Indicadores: Discordancia de dominio, alojamiento en Linktree, envío de formulario.
• Riesgo: ALTO
The attacker attempts to steal user credentials by impersonating Shaw to trick the user into entering their login details. The site is likely using JavaScript to redirect a click to an actual login form, or exfiltrate the user credentials directly to an attacker controlled server
User is redirected to a malicious site after clicking the CTA button.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain