Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FDC1BA7661209DF741A3D6D0BAFAEB5B71C282EACB4A060052DC934D0FEBD81DD311E5 |
|
CONTENT
ssdeep
|
96:1oc2ET3hZ4zjHsBRKm1ch/xgAUlefJGiLcHLZQCwD0u8WQ8vrS3eeK5NpLA8g8D1:oM3hZAHERKm1c3HhGCcHLZQRWK5r51 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b3734c4c66731959 |
|
VISUAL
aHash
|
00ffffe7e7ffffff |
|
VISUAL
dHash
|
0808324c4c300000 |
|
VISUAL
wHash
|
00a83820e7f7c3c3 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
0c28324c0c100000,0000004040400080 |
โข Threat: Credential phishing
โข Target: Microsoft users
โข Method: Impersonation and email harvesting
โข Exfil: ./guestaccess.aspx?email=A3mail%40b.c&e=1Vremd&share=EuhqrPsXrilLuCaZtpF6UIwBBhBb0oXUnNpkPNlQGS50kA
โข Indicators: Mismatched URL, form requesting email
โข Risk: Alto
The attacker attempts to steal user's email address by impersonating Microsoft's login page. User is redirected to a malicious page requesting for email.
The attacker uses social engineering techniques, like sending a fake secure link to lure the user into providing their email.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain