Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FA41C776604569B35287D1E1B770A71FBB8282C9DF73220247F8C3AC5BC6C68DF05050 |
|
CONTENT
ssdeep
|
24:n/CoAfDflGDeHhd/evMwvg4cmVmBcTitErsFpMuHNVNEIQrZAwpZA4VZSHaNHN9s:nmr9AeHhI7Vscgu+pPtvGow6Kyt1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f3c9cc2699662699 |
|
VISUAL
aHash
|
ffffe7effee6e4fc |
|
VISUAL
dHash
|
28280c08284c4c30 |
|
VISUAL
wHash
|
f6fae0e8e0e0e0d8 |
|
VISUAL
colorHash
|
070010001c0 |
|
VISUAL
cropResistant
|
28280c08284c4c30 |
• Ameaça: Phishing
• Alvo: Não especificado (provavelmente utilizadores à espera de acesso seguro a documentos)
• Método: Suplantação de identidade e recolha de credenciais através de um formulário de verificação de e-mail.
• Exfil: https://metzerplaza.com/GJlYSLyO#
• Indicadores: Domínio não relacionado, envio de formulário para domínio suspeito.
• Risco: Elevado
The attacker is attempting to steal user's email address by tricking them into entering it into a form under the guise of verifying document access.
The form submission redirects the user to a malicious domain (metzerplaza.com), which is then used to harvest the stolen data.
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain