Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19B410E50410C0E3F505280D083756F3E22DE8272EE865F0AC7FA43699ED6F8ADDE71A4 |
|
CONTENT
ssdeep
|
48:twbOIukeYON7vn4jMR2CtY/EjFLwirEWQHK:ahub7vK98FLwhnq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9973669899666699 |
|
VISUAL
aHash
|
00000018dbffffff |
|
VISUAL
dHash
|
10a94cb2b2b20c10 |
|
VISUAL
wHash
|
00000018faffffff |
|
VISUAL
colorHash
|
03007000000 |
|
VISUAL
cropResistant
|
10a94cb2b2b20c10 |
⢠Threat: Credential Harvesting
⢠Target: Enlace Digital employees/users
⢠Method: Fake login portal
⢠Exfil: JavaScript form submission
⢠Indicators: Obfuscated JS code, suspicious subdomain
⢠Risk: High
The site uses a deceptive login form to capture employee credentials.
Code is obfuscated to hide the exfiltration logic of the credentials.