Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1ED4152209024483F6553D1D8B5F4B70A66A2C282CB52168977FD639E26DEC55C8626F8 |
|
CONTENT
ssdeep
|
48:nz7cIGL6cNUVmnC64KCmAqxwpbaZVTc8auD7:nz7DGL605BP+kVlD7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9999666699999966 |
|
VISUAL
aHash
|
0000181818180000 |
|
VISUAL
dHash
|
304cb2b2b2b20410 |
|
VISUAL
wHash
|
c3c3dbdb18180000 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
b2beae969eb233a2,304cb2b2b2b20410 |
• Ameaça: Ataque de phishing para roubar credenciais
• Alvo: Clientes IONOS no Brasil
• Método: Formulário de login falso rouba e-mail e senha
• Exfil: Dados enviados para um bot do Telegram (token: 7082799777:AAGHm4hb2O6DYG_MF9tRWagXkNTXTWeF3iQ)
• Indicadores: Domínio não relacionado, envio de formulário JavaScript, token do Telegram, TLD .br
• Risco: ALTO - Roubo imediato de credenciais
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain