Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12D91B632D1502973687BC352EEE1524A4223DF9DE7130AE2CAD0053AD64CDADDCE60AD |
|
CONTENT
ssdeep
|
96:n909TBn9YLfqtqC8PLb8So8WZLhAyKGlg:y9TZmWLhJKGlg |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
99996666666698ce |
|
VISUAL
aHash
|
0018181818180000 |
|
VISUAL
dHash
|
00b2b23270703010 |
|
VISUAL
wHash
|
183c3c3c3c3c3c18 |
|
VISUAL
colorHash
|
38000000c00 |
|
VISUAL
cropResistant
|
b4b2b3b3b333b0f0,00b2b23270703010 |
• Ameaça: Distribuição de malware/Atividade suspeita
• Alvo: Usuários do yamShare
• Método: Redirecionamento de URL malicioso/Clickjacking
• Exfil: Desconhecido, mas JavaScript indica potencial exfiltração de dados.
• Indicadores: Domínio detectado como malicioso por CRDF; Ofuscação de JavaScript e envio de formulários.
• Risco: Alto
The site is flagged as malicious, and it's likely serving a malicious payload. The obfuscated Javascript may also indicate clickjacking.
The site could be used to trick a user to click something on a different page or to redirect them elsewhere.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain