Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T144E30E72B5012D7F6787BE96E9267F01F2A18235F40B1794FBA5090A4FC2FF59226324 |
|
CONTENT
ssdeep
|
3072:r7FvGzGVBFuzasIEC6IX75RcOGDIdzkkLpMY9lKkNdjc58ktu4hw/2cj+hd2jEZ1:r7FvGzGVBFuzasIEC6IX75RcOGDIdzkD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cd56b34b2caa5325 |
|
VISUAL
aHash
|
fff8f8f0f0f8ffff |
|
VISUAL
dHash
|
2c50e02322d12a2b |
|
VISUAL
wHash
|
fff830101080dbdf |
|
VISUAL
colorHash
|
060010100c0 |
|
VISUAL
cropResistant
|
2c50e02322d12a2b,f1c77d5f7d477f7c,030d719f9f4e777f,010d619585614f7e,0109d52d65456561,e1071dc919599992 |
• Amenaza: Phishing
• Objetivo: Clientes de Capital One
• Método: Suplantación de identidad a través de un sitio web similar en alojamiento gratuito.
• Exfil: Desconocido, probablemente recopilación de credenciales
• Indicadores: Alojamiento en Cloudfront, logotipo de Capital One
• Riesgo: ALTO
The attackers are trying to steal Capital One login credentials. The page likely redirects to a form to collect this information.
The website uses the Capital One brand to trick users into believing it is legitimate.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain