Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15EE3A6B2F144642B52430FE4B1A06B4CB2E7D25DCD830855B3F9979A2BC2D96CDADB1C |
|
CONTENT
ssdeep
|
3072:rynqpjhqZzUpaTTkaa45Dps3O56aV7ja46GadNxa+vsapIIa5U7aKmT2aHMZzs3W:rsa2vQ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ee6a911f15681769 |
|
VISUAL
aHash
|
00f1f1f1f1f1f1ff |
|
VISUAL
dHash
|
790727256565a3d8 |
|
VISUAL
wHash
|
00f1f19191b1f1fe |
|
VISUAL
colorHash
|
06010600000 |
|
VISUAL
cropResistant
|
45a765256565a3d8,c0c198909c9880b4,00200c7171092800,1e69f2d0d8da1807 |
• Ameaça: Falsificação de identidade
• Alvo: Usuários do Typeform
• Método: Falsificação de domínio via manipulação de subdomínio
• Exfil: Potencialmente dados do formulário
• Indicadores: Domínio incompatível, Ofuscação, Envio de formulário JS.
• Risco: Alto
The site likely aims to steal user credentials by mimicking the appearance of Typeform. Victims will be tricked into entering their login information into a fake form.
The site uses obfuscated JavaScript, which may execute malicious code that compromises the user's browser, steals data or redirects to another malicious site. The `eval` function is the biggest red flag here.
Pages with identical visual appearance (based on perceptual hash)