Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15591C651906C1F37624784D8F0A13F4F13E846C98702AF1CEFB855ED9ACFE6499221CA |
|
CONTENT
ssdeep
|
96:jgBqL48Ydf8Kv5y38TNuzdudDykD1zkLYdwdDd/VkL93bh4:jkFdfl5NzUA4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
989cc9336763d64c |
|
VISUAL
aHash
|
ffff1e0000000000 |
|
VISUAL
dHash
|
f0f0f070f8f8d86a |
|
VISUAL
wHash
|
ffff7f08000000ff |
|
VISUAL
colorHash
|
13c00010000 |
|
VISUAL
cropResistant
|
30e0c4e4e4c4c0e4,0248596332000000,f0f0f070f8f9d86a |
โข Threat: Credential Phishing
โข Target: Microsoft users
โข Method: Impersonation through a fake login page
โข Exfil: index.php
โข Indicators: Domain mismatch, Form, Obfuscation
โข Risk: High
The attacker is attempting to steal user credentials by mimicking the Microsoft login page on a deceptive domain, redirecting form submissions.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain