Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T112321F4762082D55C2F3489999102580B383DB8FCA618B7096BC4E3F1FD2AE567A1F7F |
|
CONTENT
ssdeep
|
192:cQW4MOTHjb11jztPCZw7yBNQ6VyNm4Jn3dBCWvoacAijwZB34ko/13X8Yxe+h8Uv:QOTzdiyBV3vaqMhhzv |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f2a752a0ad5aad52 |
|
VISUAL
aHash
|
e7e7e7fffffcfcfc |
|
VISUAL
dHash
|
4d4d4d0008000808 |
|
VISUAL
wHash
|
e0e0e0f80f0c0c0c |
|
VISUAL
colorHash
|
07000000056 |
|
VISUAL
cropResistant
|
4d4d4d0008000808,44cccccc8c4d06e8,454515e8caa85545,c9c8b0b09088aa8e |
• Ameaça: Phishing
• Alvo: Clientes BT/EE
• Método: Personificação via hospedagem gratuita
• Exfil: Desconhecido (provavelmente credenciais ou informações pessoais)
• Indicadores: Hospedagem gratuita, logotipo da marca, chamada para ação
• Risco: ALTO
The attacker aims to steal login credentials or other sensitive information by directing users to a fake login page. The 'Click Here to Update' prompt suggests that this is the purpose of the website.
Found 3 other scans for this domain