Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A3327233B600DD294D9B95CCF2C49A49416ED349FB3108CAB2A491BF7BC0DF069A979D |
|
CONTENT
ssdeep
|
192:rb3JyYcKcCHaJh0uuWLRMcnthWeNWbAJ4fMmUU8VCoW9d:PcKcCHSh0YbJ4fMmUFCoWD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9999666666669999 |
|
VISUAL
aHash
|
00183c0018000000 |
|
VISUAL
dHash
|
0c12b20c20000000 |
|
VISUAL
wHash
|
ffcbffc300000f00 |
|
VISUAL
colorHash
|
00007000000 |
|
VISUAL
cropResistant
|
0c12b20c20000000,0061555d6d696955 |
• Amenaza: Intento de phishing
• Objetivo: Usuarios de SurgeWeb
• Método: Suplantación de identidad a través de un formulario de inicio de sesión.
• Exfil: Probablemente credenciales de usuario.
• Indicadores: Alojamiento en Framer.app, ofuscación de Javascript.
• Riesgo: Alto
The attacker aims to steal the user's SurgeWeb credentials by presenting a fake login form. The form likely captures the entered username and password and sends them to the attacker.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain