Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BA61433590459C7B6252D39873D6FF0461CAC2A6CB0E6C00A2F4D3CCEBE7D20DEA65A5 |
|
CONTENT
ssdeep
|
48:nICYcV+cgNstRemx3YfkljfvHg68SBF0YTgl76214zeVb8JoaTokg:nClckkJfvHg68S0YTgQU4SNqomokg |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
de9c732427382537 |
|
VISUAL
aHash
|
98bcbc3c3c7cf8a0 |
|
VISUAL
dHash
|
3038316868a02949 |
|
VISUAL
wHash
|
18bcbc3c3c7cf8a0 |
|
VISUAL
colorHash
|
0fc00018000 |
|
VISUAL
cropResistant
|
3cdcdc9909e9ddde,bc3438b6f4d03464,3038316868a02949,8b8b8383838387e7 |
• Threat: Credential harvesting phishing kit targeting Adobe PDF users.
• Target: Users of Adobe PDF software.
• Method: A fake login page is used to steal usernames and passwords.
• Exfil: The destination of the stolen credentials is unknown, but it likely goes to a server controlled by the attacker.
• Indicators: The domain 'currentnewsalerts.com' does not match the official Adobe domain. The login page asks for username and password.
• Risk: HIGH - The site is designed to steal credentials and potentially compromise user accounts.
Pages with identical visual appearance (based on perceptual hash)
Found 9 other scans for this domain