Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AE2163EA9841623F44A790D5FB45AB7FF2D1C097D6160E4441FC065FABE2D04ED37100 |
|
CONTENT
ssdeep
|
24:hRfCMZ9lZRN8UjvLsVPOL81SWrdU7dLADCY7Lsp:TT9rzDjv4V884WrdU7d0DCY7Yp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c8c2373949ec6667 |
|
VISUAL
aHash
|
f87efc7c18000000 |
|
VISUAL
dHash
|
b1f8e5f1f292b2f8 |
|
VISUAL
wHash
|
fcfefc7c78580800 |
|
VISUAL
colorHash
|
1a007000000 |
|
VISUAL
cropResistant
|
686c64e46cd4e672,b1f8e5f1f292b2f8 |
• Threat: Credential Harvesting
• Target: Microsoft SharePoint Users
• Method: Fake corporate login portal
• Exfil: Likely remote database or webhook
• Indicators: Newly registered domain, generic 'SharePoint' branding
• Risk: High due to potential for corporate data breach
The site mimics a Microsoft login page to capture corporate credentials.
Targets are told they need to sign in to access 'company documents'.