Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DF2130EA9881622F44A790D5BB49AB7FF6D6C197D6160E4441FC065FA7E2D04ED36100 |
|
CONTENT
ssdeep
|
24:hRfCMZ9lZRN8UjvLsVPOL81SWrdU7dLAvw7Lsp:TT9rzDjv4V884WrdU7d0I7Yp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c8c2333949ee6667 |
|
VISUAL
aHash
|
f87efc7c18080000 |
|
VISUAL
dHash
|
b1f8e5f1f292b2f8 |
|
VISUAL
wHash
|
fcfefc7c78580800 |
|
VISUAL
colorHash
|
1a007000000 |
|
VISUAL
cropResistant
|
686c64e46cd4e672,b1f8e5f1f292b2f8 |
⢠Threat: Credential Harvesting
⢠Target: Corporate Employees
⢠Method: OAuth/SSO Phishing
⢠Exfil: Credential theft via fake Google Sign-in
⢠Indicators: Extremely recent domain, deceptive branding
⢠Risk: High
Uses a fake corporate login interface to trick users into providing their Google/SSO credentials.
Misrepresents itself as a Microsoft SharePoint portal to target corporate users.