Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1082508CE73C670269397A4B8503F018BA57B69E2B44CC899F189CCE42D74A9A4177F7C |
|
CONTENT
ssdeep
|
12288:vTcUpbu7lEDnsrWCDpgDC8bu7q1mcrns6WdwEw:Lc42EDnstep9mcrnsY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ad6d3b1212166d6d |
|
VISUAL
aHash
|
00db93ffffffffff |
|
VISUAL
dHash
|
4d32322c68d02829 |
|
VISUAL
wHash
|
008b8387bf7f1f03 |
|
VISUAL
colorHash
|
07000200030 |
|
VISUAL
cropResistant
|
3032322c4a4028a5,0000414757450000 |
• Threat: Domain expiration notice.
• Target: Hostinger domain owners.
• Method: Informing users that their domain is expired and prompting them to renew.
• Exfil: No data exfiltration.
• Indicators: Hostinger logo, legitimate domain, domain expiration notice.
• Risk: LOW - The page informs that the domain is expired, but does not appear to be stealing data.
Pages with identical visual appearance (based on perceptual hash)