Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T151D31F72B5012D7F6783BDD6E5267F05F2918536F40B1784FBA9090E4FC2EA5A227328 |
|
CONTENT
ssdeep
|
3072:iNvNWEFuzwsIEC6SX9ZFcOg3aT/ww1JUSJLKgNd58Hb23/aVhmhuMu3AwqtjXA5M:iNvNWEFuzwsIEC6SX9ZFcOg3aT/ww1t7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c2c2b919b864b78f |
|
VISUAL
aHash
|
ff70f1f5300000ff |
|
VISUAL
dHash
|
95c5e5e5e569610e |
|
VISUAL
wHash
|
ff70f1f1310000ff |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
28d5c567e585e5e5,000000100c081000,979397973d9f9f9f,0f4f2e2d2929292d,266f6c286d28303b,71e3cd9f3274ecd8,3e0f06240e3ca7bf,e5d50da669696816 |
• Ameaça: Phishing
• Alvo: Clientes da Capital One
• Método: Impersonação por meio de um site semelhante.
• Exfil: Desconhecido, devido ao envio de formulários JavaScript.
• Indicadores: Hospedagem CloudFront com o logotipo da Capital One.
• Risco: ALTO
The attacker is likely using a look-alike website, hosted on a free hosting platform, to steal user credentials. The Javascript will attempt to capture the information provided by the user.
Found 10 other scans for this domain