Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1847343BFC0420DEF1343DBA460B7FFE8928AD70AF9724490E2D856692D87D3F9142656 |
|
CONTENT
ssdeep
|
1536:MjtFvae8gfvPXjPNv9b0oC11fTqH+H0ugZUa8S/H:McGagqa/f |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d80337f8dd880df4 |
|
VISUAL
aHash
|
18181898d8d8d8d8 |
|
VISUAL
dHash
|
302872b232b13232 |
|
VISUAL
wHash
|
181838fcfcdcd8d8 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
302872b232b13232 |
• Ameaça: Phishing
• Alvo: Clientes da Shaw
• Método: Imitação via Linktree
• Exfil: Potencialmente credenciais do usuário, redirecionamento para um site malicioso
• Indicadores: Incompatibilidade de domínio, hospedagem Linktree, envio de formulário.
• Risco: ALTO
The attacker attempts to steal user credentials by impersonating Shaw to trick the user into entering their login details. The site is likely using JavaScript to redirect a click to an actual login form, or exfiltrate the user credentials directly to an attacker controlled server
User is redirected to a malicious site after clicking the CTA button.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain