Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T149A221B7600CCE3D4A5AE1D87EA776BCD153A20AF9D5189AF1C90B6B4742F748D2301B |
|
CONTENT
ssdeep
|
384:i2nRarJSnx/pGsSX+safOZM9ScPVjJqko9UtzweL3aLmogE:dnRCJSnx/GXNAOC9ScPVjJqkodkdO |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b131cecececc2433 |
|
VISUAL
aHash
|
ffcfc7c7c7c3ffff |
|
VISUAL
dHash
|
209a9e9e9e9e600e |
|
VISUAL
wHash
|
0303070303030303 |
|
VISUAL
colorHash
|
074010000c0 |
|
VISUAL
cropResistant
|
209a9e9e9e9e600e,8f839eb6a8a1898b |
• Ameaça: Roubo de credenciais
• Alvo: Usuários do Instagram
• Método: Imitação da página de login.
• Exfil: https://www.hackphreik.com/imagenes/phpfree.php
• Indicadores: Domínio incompatível, formulário de login, ofuscação detectada.
• Risco: ALTO
The site uses a fake login form to steal user credentials. When the user enters their information, it's sent to the attacker.
u0yqswxRbLp.jsPages with identical visual appearance (based on perceptual hash)
Found 4 other scans for this domain