Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D6C1DA3262309DB34193D6E0B7EAEB57B1C2439ACF46464462DC934D4FEBEC5EE211A4 |
|
CONTENT
ssdeep
|
96:1oc2ET3hZ4zjHsBRKmpk8/evqo4HAzT5xrBlwQcHLZQKwD0u83Q8vrS3eeK5NpLb:oM3hZAHERKmW8/evqD05x9lwQcHLZQZm |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b3734c4c66735919 |
|
VISUAL
aHash
|
00ffffe7e7ffffff |
|
VISUAL
dHash
|
0808324c4c300000 |
|
VISUAL
wHash
|
00ccdfc7070f0f0f |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
0c28124c0c100000,0000004040400080 |
โข Threat: Credential harvesting
โข Target: Microsoft users
โข Method: Impersonation via a fake login page.
โข Exfil: /personal/nupur_biswas_signify_com/_layouts/15/guestaccess.aspx?e=VGaQWU&share=IgDe0hk-YLDFQZq8yGFEkeWEAfOjlY_Pb3EG5nR_R6M-Iho
โข Indicators: Domain mismatch, Form asking for email, Obfuscation.
โข Risk: High
The attacker is attempting to steal a user's Microsoft credentials by tricking them into entering their email address on a fake login page that mimics the Microsoft login.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain