Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14A62FD326194253B011B0ACB7E315B1D36F7A27ECABB1A00B3F89BD1DBE6D98D911417 |
|
CONTENT
ssdeep
|
384:0nniY2RW4YKxeHOLBWjgqNLsaGF4vE6FjkcZIzeGJnskAOsGGL9oX6wnHIaKJHW6:zYKkHOLBWUqNLsanvE6FjkcZIzeensdP |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
96b425adbc456b92 |
|
VISUAL
aHash
|
06062e2eff4c2000 |
|
VISUAL
dHash
|
8c8ccccc98d8cccc |
|
VISUAL
wHash
|
06067e6effee2600 |
|
VISUAL
colorHash
|
3a007000000 |
|
VISUAL
cropResistant
|
fcdedc94c4ec8c40,f1999cc8e5f3f8f0,8c8ccccc98d8cccc |
• Ameaça: Phishing
• Alvo: Clientes da Ryanair
• Método: Personificação através de um airdrop falso
• Exfil: Desconhecido
• Indicadores: Incompatibilidade de domínio, airdrop de criptomoeda, ofuscação
• Risco: Alto
The attackers are impersonating Ryanair to trick users into participating in a fake crypto airdrop.
Creating urgency to participate and promising rewards.
jt8e3.js?lj7toybFound 3 other scans for this domain