Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10281A551906C1F3762438498F5A13F4B17E846C98702AF1CEFB854AD9ECBF64D92218A |
|
CONTENT
ssdeep
|
96:PxhBeVL48Ydfzuv5y38TNuzduhkD1zkLYdwdDd/VkL93ah4:PRe6dfzuwzUX4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
989cc9336763d64c |
|
VISUAL
aHash
|
ffff1e0000000000 |
|
VISUAL
dHash
|
f0f0f070f8f8d86a |
|
VISUAL
wHash
|
ffff7f08000000ff |
|
VISUAL
colorHash
|
13c00010000 |
|
VISUAL
cropResistant
|
30e0e4e4e4e4c0c4,0048732a49080000,f0f0f070f8f9d86a |
• Threat: Credential Harvesting
• Target: Microsoft Users
• Method: Brand impersonation via login portal
• Exfil: index.php
• Indicators: Obfuscated JS, domain mismatch
• Risk: Moderate (Simulated/Training)
The site mimics a legitimate Microsoft login portal to capture credentials input by the user.
Uses encoded JavaScript to obfuscate the form processing script.
Pages with identical visual appearance (based on perceptual hash)