Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T115A1021C12853B4F999952A2D3752E94D3E1941EC7324C58A85EE72F1C8814EEC7F9FC |
|
CONTENT
ssdeep
|
96:A3ydpoIL/N+lglAtyHL5ZiNrft5CLJWfsT3yDSxyHJHAPboRbDv72oDSZHlHD:j2bcRM3a0Qj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b2969b3131dccc99 |
|
VISUAL
aHash
|
dfe7bdc3c3ffefff |
|
VISUAL
dHash
|
394c68049e600800 |
|
VISUAL
wHash
|
1f273f3f03130303 |
|
VISUAL
colorHash
|
07018000600 |
|
VISUAL
cropResistant
|
394c68049e600800 |
• Ameaça: Phishing
• Alvo: Usuários do plala
• Método: Coleta de credenciais
• Exfil: cgi-binsso/pf/agent_sso.php
• Indicadores: Formulário em domínio suspeito, detecção de ofuscação.
• Risco: ALTO
The attacker is trying to steal the user's plala email and password by presenting a fake login form on a domain not associated with plala. This is done to gain access to the user's account.
Pages with identical visual appearance (based on perceptual hash)
Found 3 other scans for this domain