Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13B12C9D3A04454062E0DC9406B91FFC8916DC947CB2C687BB5F4795BBEAD9F0A6327E0 |
|
CONTENT
ssdeep
|
192:8tftCxtt8xLSiSphFIc4Vyn6n6RuatnoIluJndPVII:8tftC/t8tSiSpgdyn7fzsdtr |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a74d4c735933da12 |
|
VISUAL
aHash
|
0002ffefefe7e7ff |
|
VISUAL
dHash
|
0286465a48cccece |
|
VISUAL
wHash
|
000003efe7e767e7 |
|
VISUAL
colorHash
|
070020001c0 |
|
VISUAL
cropResistant
|
8626495a4dcecece,4049c2128206a6a6 |
• Ameaça: Phishing
• Alvo: Usuários DANA
• Método: Personificação e colheita de credenciais
• Exfil: tarif.php
• Indicadores: Incompatibilidade de domínio, ações de formulário, ofuscação.
• Risco: ALTO
The site impersonates the DANA login and attempts to steal the user's login credentials. The site hosts forms and utilizes potentially malicious JavaScript to collect user data.
The site uses design and content to mimic the real DANA service, to induce users to enter their information.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain