Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CA62B732B210313F129702C1BF52271EE26A9543E1161E1889FDA35D4BE9F8DEE36F56 |
|
CONTENT
ssdeep
|
384:xK1gCNcowjlIIAA2YiHPAjtJbsEC6PCfRP+0Fs1:xK1gCNc5II43PIzs6PmK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8343fe1839f3413e |
|
VISUAL
aHash
|
0000000000ffffff |
|
VISUAL
dHash
|
ccc7c7ddfff82822 |
|
VISUAL
wHash
|
0030700103ffffff |
|
VISUAL
colorHash
|
0a0000001c0 |
|
VISUAL
cropResistant
|
f0042d2d2cc4222b,ccc7c7c7cddfeff8 |
• Ameaça: Phishing/Roubo de credenciais
• Alvo: Clientes do Opportunity Bank
• Método: Falsificação de domínio
• Exfil: Credenciais de login
• Indicadores: Domínio suspeito (gr.com)
• Risco: Alto
The site mimics a legitimate banking portal to solicit login information from victims.
Uses a domain that sounds professional but is not registered to the entity.