Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15591C651906C1F37624784D8F0A13F4F13E846C98702AF1CEFB855ED9ACFE6499221CA |
|
CONTENT
ssdeep
|
96:jgBqL48Ydf8Kv5y38TNuzdudDykD1zkLYdwdDd/VkL93bh4:jkFdfl5NzUA4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
989cc9336763d64c |
|
VISUAL
aHash
|
ffff1e0000000000 |
|
VISUAL
dHash
|
f0f0f070f8f8d86a |
|
VISUAL
wHash
|
ffff7f08000000ff |
|
VISUAL
colorHash
|
13c00010000 |
|
VISUAL
cropResistant
|
30e0c4e4e4c4c0e4,0248596332000000,f0f0f070f8f9d86a |
• Amenaza: Phishing de credenciales
• Objetivo: Usuarios de Microsoft
• Método: Suplantación de identidad a través de una página de inicio de sesión falsa
• Exfil: index.php
• Indicadores: Coincidencia de dominio, Formulario, Ofuscación
• Riesgo: Alto
The attacker is attempting to steal user credentials by mimicking the Microsoft login page on a deceptive domain, redirecting form submissions.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain