Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T146713813749C682B0BB5636C7D61A76C975385A38B6A0F4222904E4FBDE2F42CC451AF |
|
CONTENT
ssdeep
|
48:n/E1vuihEbBL3wLLHr8Ap6Bwqh0dBXI+/XZkH/rmFRq8cArORlrzKY4Asau/QkIy:nZtL3wLsAsWV+Hg9 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec6c9292c3c56d6c |
|
VISUAL
aHash
|
2c00003200ffffff |
|
VISUAL
dHash
|
48b6b656890e2c00 |
|
VISUAL
wHash
|
0e0e020000ffffff |
|
VISUAL
colorHash
|
070000021c0 |
|
VISUAL
cropResistant
|
48b6b656890e2c00 |
• Ameaça: Kit de phishing para roubo de credenciais
• Alvo: Usuários do Facebook
• Método: Formulário falso que rouba email e senha
• Exfil: Dados enviados para https://sso-auth.com/kzPTMP0DWcE
• Indicators: Domínio não corresponde, domínio de registro recente, formulário detectado
• Risk: CRÍTICO - Roubo imediato de credenciais
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain