Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1ADA19BB0A082BA3B01D7C3D5AA35676E73E686D5EE439B0903F4D34D8ECAF56DC11891 |
|
CONTENT
ssdeep
|
96:ntxhfJJiVlOrpnz6zFxJvmLz5jCkF0mFqjoES1Qeb:tVJiIMwjCxPj3GQQ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8e19394edcc94e4e |
|
VISUAL
aHash
|
000301ff3430ffff |
|
VISUAL
dHash
|
72dbdbb46465a545 |
|
VISUAL
wHash
|
000301ff30b0ffff |
|
VISUAL
colorHash
|
07207000000 |
|
VISUAL
cropResistant
|
8282e2eaeae28282,dbdf9b646565a545,63fa1adbdbef9dde,d9e6766663697926,4c9736666d595932,adccd9b3b7b7beb6,616c6c5e1e7e7e7c,1d06028602029a9a |
• Threat: E-commerce phishing targeting Amazon customers.
• Target: Users who access the Amazon clone hosted on Vercel.
• Method: Displaying a fake Amazon homepage to steal credentials and personal information if a user tries to login.
• Exfil: Unknown, likely data sent to a server controlled by the attacker.
• Indicators: Free hosting, domain mismatch, Amazon logo impersonation.
• Risk: HIGH - Potential credential theft and personal data compromise.
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain