Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AD418530422C582E9063C6DCB6FBDE162395C262DB5710649AFC92BD4BD7D95DC370C9 |
|
CONTENT
ssdeep
|
48:Kl5n6iaIdu1w2T0ffO/Sm10BKVAMIaMIDTd:0me64HO/H8aJHd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc1973665919666e |
|
VISUAL
aHash
|
00ffffffffffef10 |
|
VISUAL
dHash
|
100cb2b2b2344a00 |
|
VISUAL
wHash
|
00d0f8f81f1fff00 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
200c32b2b2240a00,0008117171498400 |
• Ameaça: Phishing
• Alvo: Potencialmente qualquer usuário
• Método: Impersonação
• Exfil: Credenciais
• Indicadores: Formulário de login genérico, domínio não relacionado.
• Risco: Alto
The site uses a fake login form to collect user credentials.
Captured credentials will be sent to the attackers through the telegram bot token.
| ID | Português | Inglês | Trigger |
|---|---|---|---|
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain