Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T120719430A0212527531B0EE9B9A52B0D34A7C31ECB4214103A9E93E51FF3DF5EC1A2A4 |
|
CONTENT
ssdeep
|
96:n2ceMTIydgjke4Nbd6lS4I0sbC4bnvKTSQ:TeDYNIlSu8/i/ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
94b979e6649909e6 |
|
VISUAL
aHash
|
07071f1f171f7f00 |
|
VISUAL
dHash
|
3f3f7ffee4fcf0f8 |
|
VISUAL
wHash
|
070f0f1f173f3f00 |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
3f3f7ffae4fcf8f8,f0f2f3f3f2f0f0f0 |
• Threat: Credential harvesting phishing attack
• Target: Microsoft users
• Method: Fake Microsoft login page stealing email and password
• Exfil: Data sent to /landingpages/7ce652d6-3f52-48de-8c1b-8d3be0f7c1e4/B3HlxmPHs95cvNb095b7QJnLxfdPDdOb54Xpmw5pkS8
• Indicators: Domain mismatch (solutionfun.info vs microsoft.com), form submission via JavaScript
• Risk: CRITICAL - Real-time credential theft
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain