Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C902866090BA6D3F520781EDA7A52F12A6A7C345CBD34226C2FED78C0FE9C51DB02554 |
|
CONTENT
ssdeep
|
192:nnG6Zmzd3LnRumGqnR4Y06GY4T4s3ogQF:nGcOd3LnRumGqnR4Y06Gn8+oPF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cccc333366cccc99 |
|
VISUAL
aHash
|
1818181800000000 |
|
VISUAL
dHash
|
3032b23210000000 |
|
VISUAL
wHash
|
1c1c1c1c1c1c0c0c |
|
VISUAL
colorHash
|
00000038000 |
|
VISUAL
cropResistant
|
8080808080808080,808080c0c0808080,3032b23210000000 |
• Amenaza: Phishing de credenciales
• Objetivo: Usuarios de SwissPass
• Método: Suplantación de identidad con un formulario de inicio de sesión falso
• Exfil: s/1.php
• Indicadores: Discordancia de dominio, javascript ofuscado, datos del formulario.
• Riesgo: ALTO
The attacker aims to steal SwissPass login credentials by mimicking the official login page and capturing user input.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain