Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10F41A7B6604569B75287D1F1BB70A71FBB8282C9DF63220257F9C3AC5BD6C58DE05050 |
|
CONTENT
ssdeep
|
24:n/CoAfDflGDeHhd/evMwvg4A0VmBcTitErsFpMuHNVNEIQrZAwpZA4VZSHaNHN9s:nmr9AeHhIA0Vscgu+pPtvGow6Kyt1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f3c9cc2699662699 |
|
VISUAL
aHash
|
ffffe7effee6e4fc |
|
VISUAL
dHash
|
28280c08284c4c30 |
|
VISUAL
wHash
|
f6fae0e8e0e0e0d8 |
|
VISUAL
colorHash
|
070010001c0 |
|
VISUAL
cropResistant
|
28280c08284c4c30 |
• Ameaça: Roubo de credenciais
• Alvo: Usuários de potenciais serviços de acesso a documentos
• Método: Phishing de verificação de e-mail
• Exfil: https://nextjs.gegava.biz.pl/m33vS@OBe/#
• Indicadores: Domínio não relacionado, ação de formulário suspeita, marca genérica
• Risco: Alto
The attacker is attempting to steal user credentials (email address) by mimicking a document access login page.
The suspicious form action suggests that submitted credentials might be sent to a phishing URL for exfiltration.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain