Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T149D1876490086A67C1C391E4F7F2AB1B75A0C348D74367009AFD935DABDBCE8C6461E5 |
|
CONTENT
ssdeep
|
192:UJ7ZIIIIIFDrPLMo+WD+S7uK0LzLBGtpnkVdiLB9:UJZIIIIIlPLv+WDZuldepn6did9 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f19ed0e0e0931f0f |
|
VISUAL
aHash
|
e0e0e0e0e0e0e0e0 |
|
VISUAL
dHash
|
8080480086828080 |
|
VISUAL
wHash
|
f8f8fcf0e0e0e0e0 |
|
VISUAL
colorHash
|
02007000000 |
|
VISUAL
cropResistant
|
5072530002020202,282494a6929651ca,0000600c940c0000 |
• Ameaça: Phishing
• Alvo: Usuários da La Banque Postale
• Método: Falsificação de identidade
• Exfil: Bot do Telegram (8414960047:AAGOIbZ6HXXHJteWlaIsaZ8Pv5Ns6HzqLAE) pode roubar credenciais.
• Indicadores: Hospedagem gratuita, logotipo da marca, formulário.
• Risco: Alto
The phishing site attempts to steal La Banque Postale credentials by presenting a login form designed to mimic the legitimate site.
Stolen credentials are likely sent to a Telegram bot (8414960047:AAGOIbZ6HXXHJteWlaIsaZ8Pv5Ns6HzqLAE), enabling the attacker to access the victim's account.
| ID | Português | Inglês | Trigger |
|---|---|---|---|
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain