Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AD418530422C582E9063C6DCB6FBDE162395C262DB5710649AFC92BD4BD7D95DC370C9 |
|
CONTENT
ssdeep
|
48:Kl5n6iaIdu1w2T0ffO/Sm10BKVAMIaMIDTd:0me64HO/H8aJHd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc1973665919666e |
|
VISUAL
aHash
|
00ffffffffffef10 |
|
VISUAL
dHash
|
100cb2b2b2344a00 |
|
VISUAL
wHash
|
00d0f8f81f1fff00 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
200c32b2b2240a00,0008117171498400 |
• Amenaza: Phishing de credenciales
• Objetivo: No especificado
• Método: Imita una página de inicio de sesión.
• Exfil: Potencialmente Telegram (basado en información extraída).
• Indicadores: Formulario de inicio de sesión genérico, solicitud de contraseña, marca desconocida.
• Riesgo: Alto
The site is designed to trick users into entering their credentials on a fake login page.
Stolen credentials might be sent through a Telegram bot, allowing attackers to access user accounts.
| ID | Portugués | Inglés | Trigger |
|---|---|---|---|
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain