Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T181412099108E362B9623E1E0F60ABF07F1C68487DD7ABE0090FE85D5C6D4F04E46A061 |
|
CONTENT
ssdeep
|
24:xC/oLlie1ol3JAZcfWoy+97fef+O7b7ZIJKQqtIJBQffQksuQrkusrPC+ROtd1YH:jAUoJJCcfWo7lO7BEmyRkprC+ROtXSZL |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8ce43399cc66b399 |
|
VISUAL
aHash
|
ffffdbdb18000000 |
|
VISUAL
dHash
|
96969696323004b1 |
|
VISUAL
wHash
|
fffffff318000000 |
|
VISUAL
colorHash
|
31000000e00 |
|
VISUAL
cropResistant
|
96969696323004b1 |
• Threat: Credential harvesting phishing kit targeting Spotify users.
• Target: Spotify users.
• Method: Fake Spotify login page on a free hosting platform, designed to steal email/username and password.
• Exfil: Unknown, likely sent to a remote server controlled by the attacker.
• Indicators: Free hosting on github.io, brand impersonation, login form.
• Risk: HIGH - Credentials can be compromised immediately.
Pages with identical visual appearance (based on perceptual hash)
Found 4 other scans for this domain