Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C27195709294B43E08C5C3D8B7A17F2A27C28195E742082953EACB2E8FD7E50DC019E9 |
|
CONTENT
ssdeep
|
48:GjPCeNmTNMgEMFIiGy5a9O/qIXmQJIkQSqyBhor9ak18JRQ9GEjVsJRp7ic1dqQr:GjiERlynmQKyzKqssfBqK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d71a5d2a772a5522 |
|
VISUAL
aHash
|
00fffffffffffffe |
|
VISUAL
dHash
|
28004d686810010e |
|
VISUAL
wHash
|
001c2737270f1f06 |
|
VISUAL
colorHash
|
07000038040 |
|
VISUAL
cropResistant
|
309964694810010e,00000288988c4208 |
• Amenaza: Intento de phishing que suplanta a Aruba.it
• Objetivo: Clientes de Aruba.it
• Método: Mostrar una página de pago falsa para la renovación del dominio
• Exfil: Exfiltración de datos desconocida (probablemente información financiera)
• Indicadores: Dominio climbwest.com.au, que no coincide con Aruba.it
• Riesgo: ALTO - Intento de robo de información financiera.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain